@wagni_bot/jupiter-sdk@1.0.0
Malicious code in @wagni_bot/jupiter-sdk (npm)
Analysis
@wagni_bot/jupiter-sdk is a combosquat of the Jupiter DEX SDK. On install (both preinstall and postinstall hooks), it runs a wallet and credential harvester that: (1) enumerates Solana wallet keys from ~/.config/solana/id.json and ~/.solana/; (2) steals Ethereum keystores from ~/.ethereum/keystore; (3) hunts Bitcoin and Litecoin wallet files; (4) recursively searches the home directory for .env, .env.local, and .env.production files; and (5) exfiltrates all stolen data along with hostname, username, and working directory via HTTP POST to 107[.]161[.]90[.]180:7777.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 11:43 AM
- analyzed
- Jul 9, 2026, 11:43 AM
Related advisories
- @wagni_bot/jupiter-sdk@1.2.0 same package
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @wagni_bot/orca-sdk@1.2.0
- @wagni_bot/eth-agent@1.1.1
- @wagni_bot/polymarket-sdk@1.1.1
- ts-eslint-jest@1.0.0
- polytrade@2.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.