chain-api-sdk@0.2.10
Malicious code in chain-api-sdk (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
chain-api-sdk is a multichain crypto wallet library that depends on mchain-sdk, a known-malicious package published by the same account. When installed, chain-api-sdk loads mchain-sdk at runtime, executing its malicious payload. The package has no install hooks of its own, making the dependency on known malware the sole attack vector — the malicious code is delivered transitively through the dependency tree.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 02:34 PM
- analyzed
- Jul 8, 2026, 02:37 PM
Related advisories
- cdc-market@99.9.9
- playerdata-core@9.9.1
- @vwfs-its/sf-sac-frontend@20.1.1
- dependency_confusions@99.9.9
- qlkube@1.0.0
- @comcastdevxplatforms/plugin-tenancyinformation@28.1.1
- @grab-food/order-sdk-web@1.0.1
- @devxprotect/plugin-devxprotect-experience@22.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.