LWA-2026-7009 MAL-2026-12499 ↗ confirmed malware

wallet-analytics@1.4.8

Malicious code in wallet-analytics (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

wallet-analytics@1.4.8 is a combosquat package impersonating a blockchain analytics SDK. Its main entry point (index.js) contains a remote code execution downloader: on import, it fetches a payload from hxxps://46[.]183[.]25[.]232:45000/icons/109 and executes the response body via new Function() with full Node.js globals (require, process, Buffer, console), giving the attacker arbitrary code execution in the installer's environment. The package has no lifecycle hooks — the payload runs immediately when the module is required. The README is a fabricated description of a blockchain analytics platform; the actual code performs none of those functions.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 02:37 AM
analyzed
Jul 22, 2026, 02:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.