LWA-2026-6522 MAL-2026-10027 ↗ confirmed malware

@wagni_bot/jupiter-sdk@1.0.0

Malicious code in @wagni_bot/jupiter-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 Channel

Analysis

@wagni_bot/jupiter-sdk is a combosquat of the Jupiter DEX SDK. On install (both preinstall and postinstall hooks), it runs a wallet and credential harvester that: (1) enumerates Solana wallet keys from ~/.config/solana/id.json and ~/.solana/; (2) steals Ethereum keystores from ~/.ethereum/keystore; (3) hunts Bitcoin and Litecoin wallet files; (4) recursively searches the home directory for .env, .env.local, and .env.production files; and (5) exfiltrates all stolen data along with hostname, username, and working directory via HTTP POST to 107[.]161[.]90[.]180:7777.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:43 AM
analyzed
Jul 9, 2026, 11:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.