shiftmarkets-sdk@2.1.0
Malicious code in shiftmarkets-sdk (npm)
Analysis
The package shiftmarkets-sdk@2.1.0 is a combosquat of the legitimate Shift Markets exchange SDK. Its postinstall hook runs dist/recon.js, which silently collects system metadata — hostname, username, sudo_user, home directory, current working directory, platform, architecture, OS release, Node.js version, DNS domain, all network interface IPs (including internal addresses), CI/CD environment flags, and the names of all environment variables — then filters for variable names matching patterns for AWS, GCP, Azure, NPM, Docker, Kubernetes, Vault, tokens, secrets, keys, passwords, credentials, GitHub, GitLab, and SSH credentials. This data is POSTed as a JSON payload to 138[.]68[.]108[.]20:80/cb. The hook swallows all errors so the install never fails. The SDK's production API endpoints point to cryptosrvc[.]com rather than the legitimate Shift Markets domain.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 03:21 PM
- analyzed
- Jul 24, 2026, 03:22 PM
Related advisories
- react-campaign-optimizer@1.0.0
- kisama-js@0.1.8
- streak-metrics-math@1.0.1
- @cryptosrvc/shift-exchange-root@3.9.9
- @cryptosrvc/shift-sdk-v4@1.0.77
- @cryptosrvc/no-brainer-sdk@1.0.18
- @shiftmarkets/shift-sdk-v4@1.0.77
- @shiftmarkets/no-brainer-sdk@1.0.18
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.