crypto-checkout-api@1.0.0
Malicious code in crypto-checkout-api (npm)
Analysis
crypto-checkout-api@1.0.0 is a trojanized package posing as a crypto checkout SDK. When imported, it fetches a remote payload from hxxps://46[.]183[.]25[.]232:45000/icons/112 and executes the response body via new Function() with full Node.js globals (require, process, Buffer, setTimeout, etc.) available, enabling arbitrary remote code execution. The package has no lifecycle hooks — the downloader runs on require/import. The README describes an unrelated blockchain analytics product ("wallet-analytics") and does not match the actual code. The C2 host is 46[.]183[.]25[.]232:45000.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 02:45 AM
- analyzed
- Jul 22, 2026, 02:45 AM
Related advisories
- sync-grove@1.0.1
- chai-as-hardened@7.0.9
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
- chai-as-verified@7.1.5
- eth-react-redirection@1.0.0
- chain-js-utils@2.1.1
- chain-await-dom@1.3.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.