MAL-2026-16096

    Dashboard / Malicious Package / MAL-2026-16096

    MAL-2026-16096

    Published: 9 Sept 2026Last Modified: 9 Sept 2026

    Summary: Malicious code in soltinel-pro (npm)

    Details: Source: amazon-inspector (01f489c47a35cb393c976988c8f12eb9b47cddac13ae4112b019adad4eefb646) postinstall.cjs is declared as the package.json postinstall script and runs automatically on npm install. The script walks parent directories for.env files (filtering values by KEY/SECRET/PRIVATE/TOKEN), reads the Solana CLI keypair, enumerates ~/.config for env/key/wallet/credentials files, reads ~/.ssh private keys (id_rsa, id_ed25519, *_rsa, *_ed25519), ~/.git-credentials, and ~/.netrc, then POSTs the file contents via https.request to a hardcoded webhook.site collector. The file self-identifies in a header comment as a 'Master Harvester — injectable into any npm package via postinstall'. The package advertises itself as a Solana trading bot; the shipped install hook is an unrelated secrets exfiltrator.

    Affected packages

    Package

    Name: soltinel-pro

    Purl: pkg:npm/soltinel-pro

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.2.1
    0.2.2
    0.2.0