@shiftmarkets/no-brainer-sdk@1.0.18
Malicious code in @shiftmarkets/no-brainer-sdk (npm)
Analysis
The package @shiftmarkets/no-brainer-sdk@1.0.18 runs a postinstall script (dist/recon.js) that collects system metadata — hostname, username, home directory, working directory, platform, architecture, OS release, Node.js version, network interface IPs, CI/CD environment flags, and the names of all environment variables — then POSTs the data as JSON to 138[.]68[.]108[.]20:80/cb. The beacon specifically enumerates environment variable names matching patterns for cloud provider credentials, API tokens, and CI/CD secrets (AWS, GITHUB, NPM, DOCKER, GITLAB, etc.) to identify high-value build environments. The package claims to be a GraphQL type generator but contains no such functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 03:17 PM
- analyzed
- Jul 24, 2026, 03:18 PM
Related advisories
- @shiftmarkets/shift-sdk-v4@1.0.77
- @shiftmarkets/shift-exchange-root@3.9.9
- gekko-mev-bot@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- system-performance-helper@1.0.1
- stellar-api-safe@1.0.8
- @tobyvalk123/tixte@1.0.2
- tracker-radar-detector@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.