LWA-2026-7098 MAL-2026-12803 ↗ confirmed malware

shiftmarkets-sdk@2.1.0

Malicious code in shiftmarkets-sdk (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1049 · System Network Connections DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package shiftmarkets-sdk@2.1.0 is a combosquat of the legitimate Shift Markets exchange SDK. Its postinstall hook runs dist/recon.js, which silently collects system metadata — hostname, username, sudo_user, home directory, current working directory, platform, architecture, OS release, Node.js version, DNS domain, all network interface IPs (including internal addresses), CI/CD environment flags, and the names of all environment variables — then filters for variable names matching patterns for AWS, GCP, Azure, NPM, Docker, Kubernetes, Vault, tokens, secrets, keys, passwords, credentials, GitHub, GitLab, and SSH credentials. This data is POSTed as a JSON payload to 138[.]68[.]108[.]20:80/cb. The hook swallows all errors so the install never fails. The SDK's production API endpoints point to cryptosrvc[.]com rather than the legitimate Shift Markets domain.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:21 PM
analyzed
Jul 24, 2026, 03:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.