LWA-2026-6527 MAL-2026-10037 ↗ confirmed malware

@wagni_bot/web3-toolkit@1.0.0

Malicious code in @wagni_bot/web3-toolkit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

On install, the package runs a preinstall/postinstall script that steals cryptocurrency wallet files, credentials, and secrets from the victim's machine. It targets Solana (id.json, ~/.config/solana, ~/.solana), Ethereum keystore files, Bitcoin and Litecoin wallets, SSH private keys (~/.ssh/id_*, deploy_*), AWS credentials (~/.aws/credentials), git credentials (~/.git-credentials), npm auth tokens (~/.npmrc), and environment files (.env, .env.local, .env.production). All stolen data is exfiltrated via HTTP POST to 107[.]161[.]90[.]180:7777, including the hostname, username, and current working directory. The package performs a recursive search up to 3 directories deep across the home directory for wallet files with known names (id.json, wallet.json, keypair.json, keystore.json, mnemonic.txt, seed.txt, etc.).

analyzed by
Leitwacht
first seen
Jul 9, 2026, 11:43 AM
analyzed
Jul 9, 2026, 11:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.