VDB
Sign up

MAL-2026-16094

Malicious code in gmgn-trading-kit (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9fd3a47d22b8a9b20523cc6fa00f3b8a73e51e057dbfc4fe0034a785219563c3) postinstall.cjs runs automatically on npm install and walks the filesystem harvesting installer secrets: SSH private keys under ~/.ssh, ~/.netrc, ~/.git-credentials, Solana keypairs, wallet.json/key.* files under ~/.config, and ~/.blockrun wallet files. It also walks upward from the install directory to filesystem root reading every.env it finds, filtering for KEY/SECRET/PRIVATE/TOKEN substrings. Each file's full contents is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/d7ab73fe-7cbc-4ed3-bf8e-7207eb06875b. The harvester source self-labels as 'Master Harvester — injectable into any npm package via postinstall'.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/gmgn-trading-kit

No fixed version published yet for gmgn-trading-kit (npm). Pin to a known-safe version or switch to an alternative.

References