Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in camelot-ammv2-periphery (npm)

0
Critical
Published: 08/11/2026 (08/11/2026, 00:00:00 UTC)
Source: GCVE Database
Product: camelot-ammv2-periphery

Description

The npm package camelot-ammv2-periphery is a malicious package impersonating Camelot DEX's AMM v2 periphery contracts. It contains no legitimate functionality and executes a malicious payload during installation via preinstall and postinstall hooks. The payload harvests sensitive environment variables, configuration files, and cryptocurrency wallet keys, then exfiltrates this data to a remote server. Two versions (1.0.0 and 1.1.0) were published, with 1.1.0 expanding the scope of harvested files and secrets. The package was published by the npm account 'mssjeep843' and is part of a cluster of malicious packages targeting similar credentials. Any environment that installed these versions should consider all harvested secrets compromised and rotate them immediately.

Affected software

npmghsa
camelot-ammv2-periphery
Affected versions
=1.1.0=1.1.1=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 16:51:33 UTC

Technical Analysis

The camelot-ammv2-periphery npm package is a malicious package that impersonates legitimate Camelot DEX AMM v2 periphery contracts but contains only a Node.js stealer payload executed automatically during installation. Version 1.0.0 collects environment variables matching sensitive keywords, configuration files such as ~/.npmrc and ~/.gitconfig, and directory listings of key credential storage locations. Version 1.1.0, published shortly after, escalates the attack by reading full contents of numerous sensitive credential files (AWS, SSH private keys, Kubernetes, Docker, Git, GCP credentials), local environment files, and cryptocurrency wallet key files from Solana, Anchor, NEAR, Sui, and Foundry keystores. The harvested data is exfiltrated via HTTPS POST to a webhook.site endpoint. The payload includes anti-analysis checks to evade sandbox detection. This malicious package is part of a set of similarly crafted packages from the same npm account targeting various DeFi and crypto projects. No legitimate contract or Solidity code is present in the package, confirming its sole purpose as a credential stealer.

Potential Impact

Installation of any affected version results in silent exfiltration of sensitive secrets including environment variables, cloud credentials, SSH keys, API tokens, and cryptocurrency wallet private keys. This compromises the confidentiality of secrets critical for cloud infrastructure, developer environments, and crypto wallets. Attackers gaining these secrets can perform unauthorized access, resource abuse, and theft of cryptocurrency assets. The malicious code runs automatically during package installation without user awareness, increasing risk of widespread compromise in developer environments that install this package.

Mitigation Recommendations

No official patch or remediation is available since this is a malicious package rather than a vulnerability in legitimate software. The vendor does not manage this package. Users who installed versions 1.0.0, 1.1.0, or 1.1.1 should immediately rotate all exposed secrets, prioritizing wallet private keys and RPC/API tokens. Treat all harvested credentials as compromised. Remove the malicious package from all environments and audit for unauthorized access. Avoid installing packages from untrusted or unknown npm accounts, especially those impersonating known projects. Monitor for similar malicious packages and report them to npm for takedown.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13773
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a7c9b46bf8831d539cdd1f7

Added to database: 08/12/2026, 16:11:50 UTC

Last enriched: 08/12/2026, 16:51:33 UTC

Last updated: 08/12/2026, 16:51:33 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses