@wagni_bot/binance-sdk@1.0.0
Malicious code in @wagni_bot/binance-sdk (npm)
Analysis
@wagni_bot/binance-sdk@1.0.0 is a combosquat package impersonating the Binance crypto exchange SDK. Both the preinstall and postinstall lifecycle hooks execute postinstall.js, which is a credential and cryptocurrency wallet harvester. On install, the script: (1) hunts Solana wallet private keys (id.json) from ~/.config/solana, ~/.solana, and ~/.local/share/solana; (2) hunts Ethereum keystore files from ~/.ethereum/keystore; (3) hunts Bitcoin and Litecoin wallet files; (4) recursively searches the home directory for wallet files, .env, .env.local, and .env.production files; (5) steals SSH private keys from ~/.ssh/; (6) steals AWS credentials from ~/.aws/credentials; (7) steals git credentials from ~/.git-credentials; (8) steals npm auth tokens from ~/.npmrc. All stolen data is exfiltrated via HTTP POST to 107[.]161[.]90[.]180:7777, along with the hostname, username, and current working directory.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 11:43 AM
- analyzed
- Jul 9, 2026, 11:43 AM
Related advisories
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/jupiter-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @wagni_bot/jupiter-sdk@1.0.0
- @wagni_bot/eth-agent@1.1.1
- @wagni_bot/polymarket-sdk@1.1.1
- ts-eslint-jest@1.0.0
- polytrade@2.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.