LWA-2026-6016 MAL-2026-6522 ↗ confirmed malware

@epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.2-pentest

Malicious code in @epsteinlovekids483/crossmint-wallets-sdk-pentest (npm)

Analysis

A trojanized clone of the @crossmint/wallets-sdk npm package, published under a different scope with a -pentest suffix. The package ships a file dist/shai-hulud.js loaded on every require()/import of the main entry point. On execution it: harvests environment variables matching token/secret patterns (TOKEN, KEY, SECRET, PASS, SEED, MNEMONIC, WALLET, PRIVATE, CREDENTIAL, API_KEY, AWS, AZURE, GCP, STRIPE, SLACK, TWILIO, DOCKER, NPM, GITHUB, TURBO, NEXT_PUBLIC, OIDC, ACTIONS); executes `gh auth token` to extract the GitHub CLI token; reads ~/.npmrc (npm tokens), ~/.aws/credentials (AWS access keys), SSH private keys from ~/.ssh/; base64-encodes all stolen data and POSTs it to 127[.]0[.]0[.]1:8052/exfil as JSON; writes the stolen data to ~/.shai-hulud; and appends `node ~/.shai-hulud &` to ~/.bashrc for persistence on shell startup.

analyzed by
Leitwacht
first seen
Jun 26, 2026, 03:32 PM
analyzed
Jun 26, 2026, 03:34 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.