LWA-2026-6037 MAL-2026-6545 ↗ confirmed malware

crossmint-wallets-sdk@1.0.0

Malicious code in crossmint-wallets-sdk (npm)

Analysis

Package crossmint-wallets-sdk is a trojanized clone impersonating Crossmint (a real web3 wallet infrastructure company). Both its preinstall.js and index.js (the install hook) harvest sensitive credentials from the victim's machine. Preinstall.js collects environment variables matching TOKEN/KEY/SECRET/PASS/SEED/MNEMONIC/WALLET/PRIVATE/CREDENTIAL/API_KEY/AWS/AZURE/GCP, reads ~/.npmrc, and runs `gh auth token` to capture the GitHub CLI token. Index.js additionally reads ~/.aws/credentials, ~/.config/solana/id.json (Solana wallet private keys), and all SSH private keys from ~/.ssh/. All stolen data is base64-encoded and POSTed to 127[.]0[.]0[.]1:8052/exfil for exfiltration or onward relay. This is a credential-theft worm (Shai-Hulud pattern) targeting NPM tokens, GitHub tokens, AWS credentials, cryptocurrency wallets, and SSH keys.

analyzed by
Leitwacht
first seen
Jun 27, 2026, 03:34 AM
analyzed
Jun 27, 2026, 09:21 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.