LWA-2026-7092 MAL-2026-12509 ↗ confirmed malware

@shiftmarkets/shift-exchange-root@3.9.9

Malicious code in @shiftmarkets/shift-exchange-root (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package @shiftmarkets/shift-exchange-root@3.9.9 is a trojanized math utility. The postinstall hook runs dist/recon.js, which collects host metadata (hostname, username, home directory, working directory, platform, architecture, OS release, Node.js version), network interface IPs, CI/CD environment flags, and the NAMES of environment variables matching patterns like TOKEN, SECRET, KEY, AWS, NPM, GITHUB, GITLAB, SSH, DOCKER, KUBE, VAULT, CRED. This data is serialized as JSON and POSTed to hxxp://138[.]68[.]108[.]20:80/cb. The hook uses '|| true' to silently swallow errors and never break the install. The legitimate dist/index.js exports math functions (sum, multiply, divide, subtract, percent) to disguise the package as a normal dependency.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:16 PM
analyzed
Jul 24, 2026, 03:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.