@wagni_bot/pumpfun-sdk@1.0.0
Malicious code in @wagni_bot/pumpfun-sdk (npm)
Analysis
A trojanized clone of the Pump[.]fun SDK. On npm install, the preinstall/postinstall hook runs postinstall.js which scans the victim's home directory for crypto wallet files (Solana id.json, Ethereum keystore, Bitcoin/Litecoin wallets), .env files, SSH private keys, AWS credentials (~/.aws/credentials), .git-credentials, and .npmrc files containing auth tokens. All discovered credentials and wallet keys are exfiltrated via HTTP POST to 107[.]161[.]90[.]180:7777, along with the hostname, username, and working directory. The package has no repository and no legitimate SDK functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 11:43 AM
- analyzed
- Jul 9, 2026, 11:43 AM
Related advisories
- @wagni_bot/pumpfun-sdk@1.2.0 same package
- @wagni_bot/jupiter-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @wagni_bot/orca-sdk@1.2.0
- @wagni_bot/web3-toolkit@1.0.0
- @wagni_bot/binance-sdk@1.0.0
- @wagni_bot/jupiter-sdk@1.0.0
- @wagni_bot/eth-agent@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.