@wagni_bot/orca-sdk@1.0.0
Malicious code in @wagni_bot/orca-sdk (npm)
Analysis
On install, the package runs postinstall.js (via both preinstall and postinstall hooks). The script fingerprints the host (hostname, username, current working directory) and then systematically hunts for and exfiltrates crypto wallet files (Solana id.json, Ethereum keystore, Bitcoin/Litecoin wallet.dat, and 20+ other wallet filenames), environment variable files (.env, .env.local, .env.production), SSH private keys (id_*, deploy_*, config, authorized_keys), AWS credentials (~/.aws/credentials), git-credentials, and npm auth tokens (~/.npmrc containing authToken). All stolen data is POSTed as JSON to hxxp://107[.]161[.]90[.]180:7777.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 11:43 AM
- analyzed
- Jul 9, 2026, 11:43 AM
Related advisories
- @wagni_bot/orca-sdk@1.2.0 same package
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/jupiter-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- atlasora-shared@1.0.0
- new-helper@5.8.1
- hex-type@3.0.2
- streak-kit-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.