MAL-2026-12802

    Dashboard / Malicious Package / MAL-2026-12802

    MAL-2026-12802

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in shift-v4-sdk (npm)

    Details: Source: amazon-inspector (e86de9ce7bfa06a95a3e4d6c68f188d2c8c8b35537645e94a2fb3fee4c1e0e81) [email protected] is a typosquat of the scoped package @shiftforex/shift-sdk-v4 (self-identified as such in a comment inside dist/index.js). Its postinstall script dist/recon.js runs automatically on npm install and collects the installer's hostname, user, sudo_user, home directory, cwd, DNS domain (via dnsdomainname), network interfaces and IP addresses, the full list of process.env variable names, and a filtered subset of env-var names matching credential-shaped patterns (AWS, GCP, AZURE, NPM, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, SSH). The JSON blob is POSTed over plaintext HTTP to http://138.68.108.20/cb. An in-file comment framing this as 'non-sensitive telemetry' contradicts the actual behavior (host fingerprint plus secret-shaped env-var name enumeration is reconnaissance for follow-on targeting).

    Affected packages

    Package

    Name: shift-v4-sdk

    Purl: pkg:npm/shift-v4-sdk

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.5
    MAL-2026-12802 | CVE-DB