wallet-analytics@1.4.8
Malicious code in wallet-analytics (npm)
Analysis
wallet-analytics@1.4.8 is a combosquat package impersonating a blockchain analytics SDK. Its main entry point (index.js) contains a remote code execution downloader: on import, it fetches a payload from hxxps://46[.]183[.]25[.]232:45000/icons/109 and executes the response body via new Function() with full Node.js globals (require, process, Buffer, console), giving the attacker arbitrary code execution in the installer's environment. The package has no lifecycle hooks — the payload runs immediately when the module is required. The README is a fabricated description of a blockchain analytics platform; the actual code performs none of those functions.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 02:37 AM
- analyzed
- Jul 22, 2026, 02:37 AM
Related advisories
- luluking2@0.0.1
- luluking1@0.0.1
- @apexfnd/apex@1.0.1
- poly-custom-api@5.3.1
- alpha-helper@1.3.4
- tailwindcss-form-components@1.5.0
- async-mutex-hook@2.1.0
- chai-foundry@7.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.