LWA-2026-6526 MAL-2026-10034 ↗ confirmed malware

@wagni_bot/pumpfun-sdk@1.0.0

Malicious code in @wagni_bot/pumpfun-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

A trojanized clone of the Pump[.]fun SDK. On npm install, the preinstall/postinstall hook runs postinstall.js which scans the victim's home directory for crypto wallet files (Solana id.json, Ethereum keystore, Bitcoin/Litecoin wallets), .env files, SSH private keys, AWS credentials (~/.aws/credentials), .git-credentials, and .npmrc files containing auth tokens. All discovered credentials and wallet keys are exfiltrated via HTTP POST to 107[.]161[.]90[.]180:7777, along with the hostname, username, and working directory. The package has no repository and no legitimate SDK functionality.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:43 AM
analyzed
Jul 9, 2026, 11:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.