layer2-sdk@1.0.1
Malicious code in layer2-sdk (npm)
Analysis
layer2-sdk@1.0.1 is a trojanized combosquat package impersonating a multi-chain L2 SDK. The index.js file contains a benign-looking chain-data module followed by a hidden dropper that waits 37 seconds, then decodes a base64 payload from test/fixtures/keypairs.dat and writes it to ~/.cache-db/.node-sync/syncd.js. The dropper establishes OS-level persistence via crontab (Linux), schtasks "WinNodeSync" (Windows), or a launchd plist "com.apple.syncd" (macOS), then spawns the payload as a detached background process. The dropped payload hunts for Solana and Ethereum wallet keys, seed phrases, .env files, SSH private keys, and shell configuration files (.bashrc, .zshrc, .profile) across common directories. Found credentials are encrypted with an embedded RSA-4096 public key and exfiltrated to api[.]pinata[.]cloud (Pinata IPFS) using hardcoded API credentials. The payload checks a GitHub gist (gist[.]githubusercontent[.]com/juang55/b298754cb72942b1cdcf02ccd45cde2f/raw/cfg.txt) and IPFS CIDs on gateway[.]pinata[.]cloud, ipfs[.]io, and cloudflare-ipfs[.]com for activation signals before running. It also verifies the machine is idle (via w, xprintidle, ioreg, or PowerShell) to evade detection.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 07:49 AM
- analyzed
- Jul 14, 2026, 07:51 AM
Related advisories
- arb-kit@1.0.1
- eth-dev@1.0.2
- abi-encode@1.0.0
- chunk-parser@1.0.0
- free-anthropic-claude@5.3.0
- sort-btree@2.1.4
- npm-scanner@1.0.0
- noon-contracts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.