@shiftmarkets/shift-exchange-root@3.9.9
Malicious code in @shiftmarkets/shift-exchange-root (npm)
Analysis
The package @shiftmarkets/shift-exchange-root@3.9.9 is a trojanized math utility. The postinstall hook runs dist/recon.js, which collects host metadata (hostname, username, home directory, working directory, platform, architecture, OS release, Node.js version), network interface IPs, CI/CD environment flags, and the NAMES of environment variables matching patterns like TOKEN, SECRET, KEY, AWS, NPM, GITHUB, GITLAB, SSH, DOCKER, KUBE, VAULT, CRED. This data is serialized as JSON and POSTed to hxxp://138[.]68[.]108[.]20:80/cb. The hook uses '|| true' to silently swallow errors and never break the install. The legitimate dist/index.js exports math functions (sum, multiply, divide, subtract, percent) to disguise the package as a normal dependency.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 03:16 PM
- analyzed
- Jul 24, 2026, 03:17 PM
Related advisories
- @shiftmarkets/shift-sdk-v4@1.0.77
- @shiftmarkets/no-brainer-sdk@1.0.18
- system-performance-helper@1.0.1
- n8n-nodes-port-scanner@1.0.0
- react-campaign-optimizer@1.0.0
- search-from-search@999.99.99
- sync-external@1.6.0
- buffer-wrap-67d7@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.