LWA-2026-7093 MAL-2026-12508 ↗ confirmed malware

@shiftmarkets/no-brainer-sdk@1.0.18

Malicious code in @shiftmarkets/no-brainer-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package @shiftmarkets/no-brainer-sdk@1.0.18 runs a postinstall script (dist/recon.js) that collects system metadata — hostname, username, home directory, working directory, platform, architecture, OS release, Node.js version, network interface IPs, CI/CD environment flags, and the names of all environment variables — then POSTs the data as JSON to 138[.]68[.]108[.]20:80/cb. The beacon specifically enumerates environment variable names matching patterns for cloud provider credentials, API tokens, and CI/CD secrets (AWS, GITHUB, NPM, DOCKER, GITLAB, etc.) to identify high-value build environments. The package claims to be a GraphQL type generator but contains no such functionality.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:17 PM
analyzed
Jul 24, 2026, 03:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.