LWA-2026-6524 MAL-2026-10022 ↗ confirmed malware

@wagni_bot/binance-sdk@1.0.0

Malicious code in @wagni_bot/binance-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

@wagni_bot/binance-sdk@1.0.0 is a combosquat package impersonating the Binance crypto exchange SDK. Both the preinstall and postinstall lifecycle hooks execute postinstall.js, which is a credential and cryptocurrency wallet harvester. On install, the script: (1) hunts Solana wallet private keys (id.json) from ~/.config/solana, ~/.solana, and ~/.local/share/solana; (2) hunts Ethereum keystore files from ~/.ethereum/keystore; (3) hunts Bitcoin and Litecoin wallet files; (4) recursively searches the home directory for wallet files, .env, .env.local, and .env.production files; (5) steals SSH private keys from ~/.ssh/; (6) steals AWS credentials from ~/.aws/credentials; (7) steals git credentials from ~/.git-credentials; (8) steals npm auth tokens from ~/.npmrc. All stolen data is exfiltrated via HTTP POST to 107[.]161[.]90[.]180:7777, along with the hostname, username, and current working directory.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:43 AM
analyzed
Jul 9, 2026, 11:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.