@wagni_bot/solana-sdk@1.0.0
Malicious code in @wagni_bot/solana-sdk (npm)
Analysis
@wagni_bot/solana-sdk@1.0.0 is a combosquat of the legitimate @solana/web3.js SDK. On install (both preinstall and postinstall hooks), it executes postinstall.js which hunts the victim's filesystem for cryptocurrency wallet keys (Solana id.json, Ethereum keystores, Bitcoin/Litecoin wallets, Phantom/MetaMask files, seed/mnemonic backups), SSH private keys, AWS credentials (~/.aws/credentials), git credentials (~/.git-credentials), npm auth tokens from ~/.npmrc, and .env files. All stolen data is exfiltrated via HTTP POST to 107[.]161[.]90[.]180:7777. The package has no repository, no legitimate SDK functionality, and its sole purpose is credential theft.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 11:43 AM
- analyzed
- Jul 9, 2026, 11:43 AM
Related advisories
- @wagni_bot/solana-sdk@1.2.0 same package
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/jupiter-sdk@1.2.0
- @wagni_bot/orca-sdk@1.2.0
- @wagni_bot/orca-sdk@1.0.0
- @wagni_bot/binance-sdk@1.0.0
- @wagni_bot/jupiter-sdk@1.0.0
- @wagni_bot/eth-agent@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.