ts-bn-lint-helper@3.1.19
Malicious code in ts-bn-lint-helper (npm)
Analysis
The package is an information-stealer that searches the working directory for credential and wallet files — specifically id.json (Solana CLI wallet keypair), config.toml, Config.toml, config.json, env, and .env — reads them, and POSTs them to hxxps://data-stream[.]space/api/v1 as binary attachments. It also collects the victim's shell history from ~/.bash_history, ~/.zsh_history, ~/.fish_history, ~/.sh_history, and PowerShell PSReadLine history, and exfiltrates those too. Each upload is prefixed with the system USER and local IP address for victim identification. The exfiltration endpoint is data-stream[.]space (HTTPS).
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 11:40 AM
- analyzed
- Jun 20, 2026, 11:41 AM
Related advisories
- atlasora-client@1.0.0
- atlasora-utils@1.0.0
- atlasora-types@1.0.0
- atlasora-sdk@1.0.0
- atlasora-config@1.0.0
- atlasora-shared@1.0.0
- atlasora-api@1.0.0
- log-taker1@0.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.