MAL-2026-15857

    Dashboard / Malicious Package / MAL-2026-15857

    MAL-2026-15857

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: Malicious code in @quantixfinance/wallet (npm)

    Details: Source: amazon-inspector (18cabdbe5d59eb5064ea44a0a73db01d23affa7975049251454f599210aa79e3) The package advertises itself as a wallet library but ships a 67-byte no-op index.js; the entire payload is a preinstall lifecycle script that fires automatically on npm install. The script iterates process.env and selects variables whose names contain any of a broad credential-related substring list (key, secret, token, pass, mnemonic, seed, private, wallet, api, rpc, infura, alchemy, supabase, database, deploy, vercel, railway, tron, contract, env, url), then bundles the matched values together with the machine hostname, current working directory, and Node.js version and POSTs the JSON to a hardcoded remote endpoint. The destination host is written as the 32-bit integer 759017974, which decodes to 45.61.177.246, and the request targets port 61289 with a per-victim GUID-shaped path. The integer-encoded host defeats plain-text URL scanning and there is no documented functionality that would justify the outbound POST.

    Affected packages

    Package

    Name: @quantixfinance/wallet

    Purl: pkg:npm/%40quantixfinance/wallet

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0