@shiftmarkets/shift-sdk-v4@1.0.77
Malicious code in @shiftmarkets/shift-sdk-v4 (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1518.001 · Security Software DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
Combosquat of the shift-sdk-v4 trading API client. On install, the postinstall hook runs dist/recon.js which collects host metadata (hostname, username, platform, architecture, network interfaces, CI environment flags) and enumerates all environment variable names, filtering for those matching secret-related patterns (AWS, TOKEN, SECRET, KEY, GITHUB, NPM, etc.). This data is POSTed as JSON to 138[.]68[.]108[.]20:80/cb. The main dist/index.js is a stub with no real trading functionality — the package's sole purpose is the reconnaissance beacon.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 03:17 PM
- analyzed
- Jul 24, 2026, 03:18 PM
Related advisories
- @shiftmarkets/no-brainer-sdk@1.0.18
- @shiftmarkets/shift-exchange-root@3.9.9
- shift-sdk-v5@5.0.1
- gekko-mev-bot@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- system-performance-helper@1.0.1
- stellar-api-safe@1.0.8
- @tobyvalk123/tixte@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.