LWA-2026-6523 MAL-2026-10031 ↗ confirmed malware

@wagni_bot/orca-sdk@1.0.0

Malicious code in @wagni_bot/orca-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1555 · Credentials from Password StoresT1005 · Data from Local SystemT1041 · Exfiltration Over C2 Channel

Analysis

On install, the package runs postinstall.js (via both preinstall and postinstall hooks). The script fingerprints the host (hostname, username, current working directory) and then systematically hunts for and exfiltrates crypto wallet files (Solana id.json, Ethereum keystore, Bitcoin/Litecoin wallet.dat, and 20+ other wallet filenames), environment variable files (.env, .env.local, .env.production), SSH private keys (id_*, deploy_*, config, authorized_keys), AWS credentials (~/.aws/credentials), git-credentials, and npm auth tokens (~/.npmrc containing authToken). All stolen data is POSTed as JSON to hxxp://107[.]161[.]90[.]180:7777.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:43 AM
analyzed
Jul 9, 2026, 11:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.