LWA-2026-6947 MAL-2026-10942 ↗ confirmed malware

aftermath-sui@99.0.0

Malicious code in aftermath-sui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Three combosquat packages (aftermath-finance, aftermathfi, aftermath-sui) targeting the Aftermath Finance SDK. On npm install, the preinstall hook runs setup.js which collects environment variables matching key/secret/token/pass/auth/private/sui/admin/deploy, the system hostname, username, current working directory, and git remote URLs, then exfiltrates the data as a JSON POST to 2[.]25[.]140[.]71:8443/aftermath/npm-dep-conf over HTTPS (with certificate validation disabled). The packages contain no legitimate SDK code — only the credential-harvesting payload.

analyzed by
Leitwacht
first seen
Jul 19, 2026, 03:55 PM
analyzed
Jul 19, 2026, 03:55 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.