MAL-2026-12347
Dashboard / Malicious Package / MAL-2026-12347
MAL-2026-12347
Summary: Malicious code in ccxt-trading (npm)
Details: Source: amazon-inspector (b0442271e1969ce5899ac9176cf8dfed0dbf8edd46fecf99ee8e3cd4f21a92d8) Package name resembles the popular ccxt library. The exported ProExchange constructor, invoked whenever a consumer instantiates any exchange through the package's exchange map, captures the caller-supplied apiKey, secret, and password, gathers host identifiers (hostname, username, homedir, timestamp), and reads a list of home-directory files including wallet.json,.env, config.json, keypair.json, id_rsa, and credentials.json. The collected data is POSTed via https.request to the hardcoded destination enjbyg3xk8l.x.pipedream.net. The destination is not configurable, not documented, and is unrelated to any exchange API.
Affected packages
Package
Name: ccxt-trading
Purl: pkg:npm/ccxt-trading
Affected ranges
Type: N/A
Events:
