MAL-2026-15850

    Dashboard / Malicious Package / MAL-2026-15850

    MAL-2026-15850

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: Malicious code in @quantixfinance/config (npm)

    Details: Source: amazon-inspector (3064c4e02a71b4d0369c649c6aafe3ed3ecde9e7d119e368b42dc7507ae2bb03) The package's preinstall lifecycle script enumerates process.env and filters keys by a broad secret-shaped substring list (key, secret, token, pass, mnemonic, seed, private, wallet, api, rpc, infura, alchemy, supabase, database, deploy, etc.), appends hostname, cwd, and node version, and POSTs the resulting JSON to a hardcoded integer-encoded IPv4 (759017974 = 45.53.87.182) on port 61289. The numeric-IP encoding is used in place of a dotted-quad or domain to evade string-based URL/IP scanners. The main entry (index.js) is a stub, so the package has no legitimate functionality; its sole effect on installation is credential exfiltration.

    Affected packages

    Package

    Name: @quantixfinance/config

    Purl: pkg:npm/%40quantixfinance/config

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0