MAL-2026-15851
Dashboard / Malicious Package / MAL-2026-15851
MAL-2026-15851
Summary: Malicious code in @quantixfinance/contracts (npm)
Details: Source: amazon-inspector (497edc9bba37d0fd2fb3de0fccd537904ae37848535519f4d334c38d8b59d3bf) The package's preinstall lifecycle script iterates process.env and filters keys for credential-shaped substrings (key, secret, token, pass, mnemonic, seed, private, wallet, rpc, infura, alchemy, api), attaches os.hostname(), process.cwd() and process.version, and POSTs the resulting JSON to a hardcoded remote host. The destination is written as an integer literal (759017974, decoding to 45.61.177.246) on port 61289 to evade string-based scanners. The package advertises itself as a contracts/ABI library and has no legitimate need to read or transmit environment secrets or host identifiers.
Affected packages
Package
Name: @quantixfinance/contracts
Purl: pkg:npm/%40quantixfinance/contracts
Affected ranges
Type: N/A
Events:
