LWA-2026-6867 MAL-2026-11007 ↗ confirmed malware

web3-terminal@2.1.6

Malicious code in web3-terminal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1098.004 · SSH Authorized KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The postinstall hook (node test.js) executes a credential harvester and SSH backdoor. The code scans the working directory for id.json, config.toml, and .env files and uploads them to hxxp://170[.]205[.]31[.]203:3000/api/v1. It then fetches an SSH public key from hxxp://170[.]205[.]31[.]203:3001/api/ssh-key, appends it to ~/.ssh/authorized_keys, enables the firewall and opens port 22 for remote access. It also fetches file-scanning patterns from the same C2 server, scans the home directory (or all drives on Windows) for matching files, and uploads them to hxxp://170[.]205[.]31[.]203:3001/api/v1. The package name (web3-terminal) is unrelated to its description (a copy of the ts-api documentation), indicating combosquatting.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 08:36 PM
analyzed
Jul 16, 2026, 08:43 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.