MAL-2026-13729

    Dashboard / Malicious Package / MAL-2026-13729

    MAL-2026-13729

    Published: 11 Aug 2026Last Modified: 12 Aug 2026

    Summary: Malicious code in dlmm-sdk (PyPI)

    Details: Source: amazon-inspector (9ddf2d03d839f7eff709e78da1d6a85226cdd3b9171dbcb59a4a95c741e0773e) The package's top-level module runs a report() routine on import, and setup.py invokes the same import at install time. The routine collects environment variables matching secret-shaped keywords (KEY, TOKEN, SECRET, AWS, GITHUB, NPM, MNEMONIC, WALLET, SOLANA, HELIUS,...), reads ~/.npmrc and ~/.gitconfig, enumerates ~/.ssh, ~/.aws, ~/.config/solana, ~/.config/anchor, and ~/.config/gcloud, and gathers hostname, username, cwd, and platform. The collected JSON is POSTed via urllib.request.urlopen to a hardcoded webhook.site endpoint (https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09). Module docstring and setup.py comment label the behavior 'environment diagnostics,' but the code path is bulk credential and host-identity exfiltration to a non-first-party collector. The package name resembles Meteora's DLMM SDK. Source: kam193 (e711193dc1874123e46e44138b8d69212d6838fdb4b4d93f84cdbc9041e74457) During import the package exfiltrates sensitive env variables (e.g. related to cloud providers, cryptocurrencies, package registries), credential files (including SSH keys, cloud credentials, package registry configuration) and dotenv files. In addition, listings of some directories, e.g. cryptocurrency wallets and cloud CLI configuration, are collected. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-dlmm Reasons (based on the campaign): - exfiltration-env-variables - dependency-confusion - crypto-related - exfiltration-credentials - files-exfiltration

    Affected packages

    Package

    Name: dlmm-sdk

    Purl: pkg:pypi/dlmm-sdk

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0