LWA-2026-7096 MAL-2026-12316 ↗ confirmed malware

@cryptosrvc/shift-exchange-root@3.9.9

Malicious code in @cryptosrvc/shift-exchange-root (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package @cryptosrvc/shift-exchange-root@3.9.9 masquerades as a math utility library but runs a system reconnaissance script in its postinstall hook. The script collects hostname, username, home directory, current working directory, OS platform/architecture/release, Node.js version, all network interface IPs (including internal addresses), DNS domain, CI/CD environment indicators, and the names of all environment variables — specifically filtering for those matching credential-related patterns (AWS, GCP, AZURE, NPM, DOCKER, KUBE, VAULT, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, SSH). This data is serialized as JSON and POSTed to hxxp://138[.]68[.]108[.]20:80/cb. The package's scope (@cryptosrvc) does not match the claimed project name in its README (@shiftforex), indicating a combosquat impersonation. The main entry point (dist/index.js) is a decoy containing benign math functions.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:18 PM
analyzed
Jul 24, 2026, 03:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.