MAL-2026-13729
Dashboard / Malicious Package / MAL-2026-13729
MAL-2026-13729
Summary: Malicious code in dlmm-sdk (PyPI)
Details: Source: amazon-inspector (9ddf2d03d839f7eff709e78da1d6a85226cdd3b9171dbcb59a4a95c741e0773e) The package's top-level module runs a report() routine on import, and setup.py invokes the same import at install time. The routine collects environment variables matching secret-shaped keywords (KEY, TOKEN, SECRET, AWS, GITHUB, NPM, MNEMONIC, WALLET, SOLANA, HELIUS,...), reads ~/.npmrc and ~/.gitconfig, enumerates ~/.ssh, ~/.aws, ~/.config/solana, ~/.config/anchor, and ~/.config/gcloud, and gathers hostname, username, cwd, and platform. The collected JSON is POSTed via urllib.request.urlopen to a hardcoded webhook.site endpoint (https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09). Module docstring and setup.py comment label the behavior 'environment diagnostics,' but the code path is bulk credential and host-identity exfiltration to a non-first-party collector. The package name resembles Meteora's DLMM SDK. Source: kam193 (e711193dc1874123e46e44138b8d69212d6838fdb4b4d93f84cdbc9041e74457) During import the package exfiltrates sensitive env variables (e.g. related to cloud providers, cryptocurrencies, package registries), credential files (including SSH keys, cloud credentials, package registry configuration) and dotenv files. In addition, listings of some directories, e.g. cryptocurrency wallets and cloud CLI configuration, are collected. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-dlmm Reasons (based on the campaign): - exfiltration-env-variables - dependency-confusion - crypto-related - exfiltration-credentials - files-exfiltration
References: https://bad-packages.kam193.eu/pypi/package/dlmm-sdk, https://pypi.org/project/dlmm-sdk/1.0.0/
Affected packages
Package
Name: dlmm-sdk
Purl: pkg:pypi/dlmm-sdk
Affected ranges
Type: N/A
Events:
