MAL-2026-16094

    Dashboard / Malicious Package / MAL-2026-16094

    MAL-2026-16094

    Published: 9 Sept 2026Last Modified: 9 Sept 2026

    Summary: Malicious code in gmgn-trading-kit (npm)

    Details: Source: amazon-inspector (9fd3a47d22b8a9b20523cc6fa00f3b8a73e51e057dbfc4fe0034a785219563c3) postinstall.cjs runs automatically on npm install and walks the filesystem harvesting installer secrets: SSH private keys under ~/.ssh, ~/.netrc, ~/.git-credentials, Solana keypairs, wallet.json/key.* files under ~/.config, and ~/.blockrun wallet files. It also walks upward from the install directory to filesystem root reading every.env it finds, filtering for KEY/SECRET/PRIVATE/TOKEN substrings. Each file's full contents is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. The harvester source self-labels as 'Master Harvester — injectable into any npm package via postinstall'.

    Affected packages

    Package

    Name: gmgn-trading-kit

    Purl: pkg:npm/gmgn-trading-kit

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.7.0
    1.7.1
    1.7.2