MAL-2026-16094
Dashboard / Malicious Package / MAL-2026-16094
MAL-2026-16094
Summary: Malicious code in gmgn-trading-kit (npm)
Details: Source: amazon-inspector (9fd3a47d22b8a9b20523cc6fa00f3b8a73e51e057dbfc4fe0034a785219563c3) postinstall.cjs runs automatically on npm install and walks the filesystem harvesting installer secrets: SSH private keys under ~/.ssh, ~/.netrc, ~/.git-credentials, Solana keypairs, wallet.json/key.* files under ~/.config, and ~/.blockrun wallet files. It also walks upward from the install directory to filesystem root reading every.env it finds, filtering for KEY/SECRET/PRIVATE/TOKEN substrings. Each file's full contents is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. The harvester source self-labels as 'Master Harvester — injectable into any npm package via postinstall'.
References: https://www.npmjs.com/package/gmgn-trading-kit/v/1.7.0, https://www.npmjs.com/package/gmgn-trading-kit/v/1.7.1, https://www.npmjs.com/package/gmgn-trading-kit/v/1.7.2
Affected packages
Package
Name: gmgn-trading-kit
Purl: pkg:npm/gmgn-trading-kit
Affected ranges
Type: N/A
Events:
