jest-formatter@1.0.0
Malicious code in jest-formatter (npm)
Analysis
jest-formatter@1.0.0 is a trojanized clone of a Jest formatter that exfiltrates the victim's credentials, crypto wallets, and sensitive files. On install, running `npm test` triggers a full data-theft pipeline: it scans the project directory and home drives for .env files, crypto wallet files (keystore, wallet.json, keypair.json, mnemonic.txt, seed.txt, credentials.json), SSH private keys (.pem/.p12/.pfx), shell history (bash/zsh/fish/PowerShell), clipboard contents, and development secrets (EVM private keys, Solana key arrays, mnemonics, AWS secrets, API tokens, npm tokens). All stolen data is uploaded via multipart HTTP POST to hxxps://trabalhos-flax[.]vercel[.]app/api/v1. The package also bundles a RAR archive (data-backup-single.rar) of unknown purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 08:13 AM
- analyzed
- Jul 9, 2026, 08:14 AM
Related advisories
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- crypto-base58@1.0.1
- pino-zod@1.0.121
- zod-pino@1.0.122
- nat-ulid@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.