@cryptosrvc/shift-exchange-root@3.9.9
Malicious code in @cryptosrvc/shift-exchange-root (npm)
Analysis
The package @cryptosrvc/shift-exchange-root@3.9.9 masquerades as a math utility library but runs a system reconnaissance script in its postinstall hook. The script collects hostname, username, home directory, current working directory, OS platform/architecture/release, Node.js version, all network interface IPs (including internal addresses), DNS domain, CI/CD environment indicators, and the names of all environment variables — specifically filtering for those matching credential-related patterns (AWS, GCP, AZURE, NPM, DOCKER, KUBE, VAULT, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, SSH). This data is serialized as JSON and POSTed to hxxp://138[.]68[.]108[.]20:80/cb. The package's scope (@cryptosrvc) does not match the claimed project name in its README (@shiftforex), indicating a combosquat impersonation. The main entry point (dist/index.js) is a decoy containing benign math functions.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 03:18 PM
- analyzed
- Jul 24, 2026, 03:20 PM
Related advisories
- @cryptosrvc/shift-sdk-v4@1.0.77
- @cryptosrvc/no-brainer-sdk@1.0.18
- @shiftmarkets/shift-sdk-v4@1.0.77
- @shiftmarkets/no-brainer-sdk@1.0.18
- @shiftmarkets/shift-exchange-root@3.9.9
- gekko-mev-bot@1.0.0
- @daylightqc/date-fmt-lite@1.1.2
- system-performance-helper@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.