approval-guardian@1.0.8
Malicious code in approval-guardian (npm)
Analysis
approval-guardian@1.0.8 is a trojanized ERC-20 approval scanner that functions as a crypto-wallet infostealer. On execution, it silently harvests browser wallet extension data (MetaMask, Phantom, Rabby, Coinbase, OKX, Keplr, Ronin, and 30+ others) from Chromium-based browser profiles, scrapes desktop wallet directories (Exodus, Electrum, Atomic, Ledger Live, Trezor Suite), enumerates password manager vaults (Bitwarden, 1Password, LastPass, KeePass, Dashlane, Keeper), and deploys a Windows keylogger via a PowerShell/C# low-level keyboard hook to capture passwords typed into wallet/extension windows. Captured passwords are used to attempt decryption of MetaMask vaults (PBKDF2+AES-GCM/CBC). All stolen data — browser Login Data, Local State, extension LevelDB stores, wallet files, password manager files, keystroke logs, and decrypted vault contents — is base64+gzip compressed and exfiltrated via POST to chainpulse-api-vf5g[.]onrender[.]com/api/v1/telemetry. The package installs persistence by copying itself to %LOCALAPPDATA%\Microsoft\EdgeUpdate\Client\msedge_update_core.js, adding a HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key (MicrosoftEdgeUpdateCore), and creating Windows scheduled tasks for ONLOGON and every-30-minute execution. The package has no repository and no verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 04:41 PM
- analyzed
- Aug 1, 2026, 04:42 PM
Related advisories
- streak-metrics-math@1.0.1
- metrics-probe-9b4c@1.0.0
- env-config-f281@1.0.0
- system-performance-helper@1.0.1
- pinokio-redis@1.0.127
- zod-pino434@1.0.127
- ddok-modal@1.0.0
- base58-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.