MAL-2026-12347

    Dashboard / Malicious Package / MAL-2026-12347

    MAL-2026-12347

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in ccxt-trading (npm)

    Details: Source: amazon-inspector (b0442271e1969ce5899ac9176cf8dfed0dbf8edd46fecf99ee8e3cd4f21a92d8) Package name resembles the popular ccxt library. The exported ProExchange constructor, invoked whenever a consumer instantiates any exchange through the package's exchange map, captures the caller-supplied apiKey, secret, and password, gathers host identifiers (hostname, username, homedir, timestamp), and reads a list of home-directory files including wallet.json,.env, config.json, keypair.json, id_rsa, and credentials.json. The collected data is POSTed via https.request to the hardcoded destination enjbyg3xk8l.x.pipedream.net. The destination is not configurable, not documented, and is unrelated to any exchange API.

    Affected packages

    Package

    Name: ccxt-trading

    Purl: pkg:npm/ccxt-trading

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12347 | CVE-DB