MAL-2026-15857
Dashboard / Malicious Package / MAL-2026-15857
MAL-2026-15857
Summary: Malicious code in @quantixfinance/wallet (npm)
Details: Source: amazon-inspector (18cabdbe5d59eb5064ea44a0a73db01d23affa7975049251454f599210aa79e3) The package advertises itself as a wallet library but ships a 67-byte no-op index.js; the entire payload is a preinstall lifecycle script that fires automatically on npm install. The script iterates process.env and selects variables whose names contain any of a broad credential-related substring list (key, secret, token, pass, mnemonic, seed, private, wallet, api, rpc, infura, alchemy, supabase, database, deploy, vercel, railway, tron, contract, env, url), then bundles the matched values together with the machine hostname, current working directory, and Node.js version and POSTs the JSON to a hardcoded remote endpoint. The destination host is written as the 32-bit integer 759017974, which decodes to 45.61.177.246, and the request targets port 61289 with a per-victim GUID-shaped path. The integer-encoded host defeats plain-text URL scanning and there is no documented functionality that would justify the outbound POST.
Affected packages
Package
Name: @quantixfinance/wallet
Purl: pkg:npm/%40quantixfinance/wallet
Affected ranges
Type: N/A
Events:
