shift-sdk-v5@5.0.1
Malicious code in shift-sdk-v5 (npm)
Analysis
The postinstall hook in dist/recon.js collects extensive system metadata — hostname, username, sudo_user, home directory, current working directory, platform, architecture, OS release, Node.js version, DNS domain, all network interfaces with internal IPs, CI/CD environment flags, and a filtered list of environment variable names matching secret-related patterns (AWS, GCP, AZURE, NPM, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, SSH). This data is serialized as JSON and POSTed to 138[.]68[.]108[.]20:80/cb. The package's main dist/index.js is a decoy trading API client stub with no real functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 03:21 PM
- analyzed
- Jul 24, 2026, 03:22 PM
Related advisories
- @shiftmarkets/shift-sdk-v4@1.0.77
- simple-date-formatter-util-14@1.0.0
- json-to-table-util@1.0.0
- text-line-parser@1.0.0
- ohcm-culture-formatting@5.0.0
- llm-traces-app@1.0.1
- starship-timeline@1.0.1
- cardano-addresses-docs@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.