LWA-2026-7313 MAL-2026-12472 ↗ confirmed malware

sui-migration-audit-rules@1.0.0

Malicious code in sui-migration-audit-rules (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

sui-migration-audit-rules@1.0.0 is a combosquat package targeting Sui blockchain developers. When required, it steals the Sui wallet keystore (~/.sui/sui.keystore) and scrapes .env files from common project directories for private keys and credentials matching PK_B64, PRIVATE_KEY, or SUI_ patterns. It also collects host metadata (OS, username, hostname, Node.js version). All stolen data is bundled into a tar.gz archive and exfiltrated via HTTP POST to 91[.]92[.]241[.]99:8080/collect. The C2 endpoint is configurable via the COLLECT_URL environment variable, defaulting to the hardcoded IP.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 07:54 AM
analyzed
Aug 1, 2026, 07:54 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.