sui-migration-audit-rules@1.0.0
Malicious code in sui-migration-audit-rules (npm)
Analysis
sui-migration-audit-rules@1.0.0 is a combosquat package targeting Sui blockchain developers. When required, it steals the Sui wallet keystore (~/.sui/sui.keystore) and scrapes .env files from common project directories for private keys and credentials matching PK_B64, PRIVATE_KEY, or SUI_ patterns. It also collects host metadata (OS, username, hostname, Node.js version). All stolen data is bundled into a tar.gz archive and exfiltrated via HTTP POST to 91[.]92[.]241[.]99:8080/collect. The C2 endpoint is configurable via the COLLECT_URL environment variable, defaulting to the hardcoded IP.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 07:54 AM
- analyzed
- Aug 1, 2026, 07:54 AM
Related advisories
- akamaijs@1.0.1
- nagixjs@2.1.6
- api-rust-sdk@2.1.6
- app-soda-layer@2.1.6
- vscode-designer-14@14.0.1
- messenger-style@1.0.1
- page-navigation@1.0.1
- app-sim-layer@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.