LWA-2026-7099 MAL-2026-12802 ↗ confirmed malware

shift-v4-sdk@1.0.5

Malicious code in shift-v4-sdk (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package shift-v4-sdk@1.0.5 masquerades as a trading API client but runs a host-reconnaissance script in its postinstall hook. The script collects the victim's hostname, username, home directory, current working directory, OS platform/arch/release, Node.js version, DNS domain, all network interface IPs (including internal addresses), CI/CD environment indicators, and the names of environment variables matching credential-related patterns (AWS, GCP, Azure, NPM, Docker, GitHub, SSH, etc.). This data is serialized as JSON and POSTed to 138[.]68[.]108[.]20:80/cb. The hook uses "|| true" to silently swallow errors so the install never fails. The package contains no real SDK code — only the recon script and a stub entry point.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:21 PM
analyzed
Jul 24, 2026, 03:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.