LWA-2026-7100 MAL-2026-12436 ↗ confirmed malware

shift-sdk-v5@5.0.1

Malicious code in shift-sdk-v5 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1033 · System Owner/User DiscoveryT1614 · System Location DiscoveryT1518.001 · Security Software DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook in dist/recon.js collects extensive system metadata — hostname, username, sudo_user, home directory, current working directory, platform, architecture, OS release, Node.js version, DNS domain, all network interfaces with internal IPs, CI/CD environment flags, and a filtered list of environment variable names matching secret-related patterns (AWS, GCP, AZURE, NPM, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, SSH). This data is serialized as JSON and POSTed to 138[.]68[.]108[.]20:80/cb. The package's main dist/index.js is a decoy trading API client stub with no real functionality.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 03:21 PM
analyzed
Jul 24, 2026, 03:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.