MAL-2026-12315

    Dashboard / Malicious Package / MAL-2026-12315

    MAL-2026-12315

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in @cryptosrvc/no-brainer-sdk (npm)

    Details: Source: amazon-inspector (7955af180bb00f4f97b5dee0c7020f9e43f4c35aa84c5ef5446dd95646eb333b) On npm install, the package's postinstall script (dist/recon.js) collects installer-side host reconnaissance — hostname, username, SUDO_USER, home directory, cwd, network interfaces including internal IPs, DNS domain via dnsdomainname, and npm lifecycle context — and enumerates process.env, filtering the key names against a regex targeting AWS, GCP, AZURE, NPM, NODE_AUTH, DOCKER, KUBE, VAULT, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, and SSH. Both the full env-name list and the credential-shaped subset are serialized and POSTed as JSON over plain HTTP to hardcoded bare IP 138.68.108.20:80/cb, with a `npm-install-telemetry/1.0` User-Agent and an inline comment framing the payload as 'NON-SENSITIVE telemetry only' despite including sudo_user, internal network layout, and credential env-var name inventory. Behavior fires automatically as a postinstall lifecycle hook.

    Affected packages

    Package

    Name: @cryptosrvc/no-brainer-sdk

    Purl: pkg:npm/%40cryptosrvc/no-brainer-sdk

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.18
    MAL-2026-12315 | CVE-DB