LWA-2026-7095 MAL-2026-12317 ↗ confirmed malware

@cryptosrvc/shift-sdk-v4@1.0.77

Malicious code in @cryptosrvc/shift-sdk-v4 (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall hook runs dist/recon.js, which collects extensive host metadata (hostname, username, sudo_user, homedir, cwd, platform, arch, node version, dns domain, all network interfaces with internal IPs, CI/CD environment flags, and all environment variable names filtered for patterns matching AWS/GCP/AZURE/NPM/TOKEN/KEY/GITHUB/CRED) and POSTs the JSON payload to 138[.]68[.]108[.]20:80/cb. The main dist/index.js is a decoy trading SDK stub; the package's real purpose is environment reconnaissance and beaconing to a hardcoded IP.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:18 PM
analyzed
Jul 24, 2026, 03:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.