LWA-2026-7097 MAL-2026-12315 ↗ confirmed malware

@cryptosrvc/no-brainer-sdk@1.0.18

Malicious code in @cryptosrvc/no-brainer-sdk (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's postinstall hook runs dist/recon.js, which collects system metadata (hostname, username, internal IP addresses, CI environment flags, and the names of environment variables matching AWS/GCP/Azure/NPM/GitHub/SSH/TOKEN/SECRET/KEY patterns) and POSTs it as JSON to 138[.]68[.]108[.]20:80/cb. The main dist/index.js is a decoy GraphQL type generator. The recon payload runs silently (exits 0 on error) and does not break installation.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:18 PM
analyzed
Jul 24, 2026, 03:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.