Malicious code in camelot-ammv2-periphery (npm)
The npm package camelot-ammv2-periphery is a malicious package impersonating Camelot DEX's AMM v2 periphery contracts. It contains no legitimate functionality and executes a malicious payload during installation via preinstall and postinstall hooks. The payload harvests sensitive environment variables, configuration files, and cryptocurrency wallet keys, then exfiltrates this data to a remote server. Two versions (1.0.0 and 1.1.0) were published, with 1.1.0 expanding the scope of harvested files and secrets. The package was published by the npm account 'mssjeep843' and is part of a cluster of malicious packages targeting similar credentials. Any environment that installed these versions should consider all harvested secrets compromised and rotate them immediately.
AI Analysis
Technical Summary
The camelot-ammv2-periphery npm package is a malicious package that impersonates legitimate Camelot DEX AMM v2 periphery contracts but contains only a Node.js stealer payload executed automatically during installation. Version 1.0.0 collects environment variables matching sensitive keywords, configuration files such as ~/.npmrc and ~/.gitconfig, and directory listings of key credential storage locations. Version 1.1.0, published shortly after, escalates the attack by reading full contents of numerous sensitive credential files (AWS, SSH private keys, Kubernetes, Docker, Git, GCP credentials), local environment files, and cryptocurrency wallet key files from Solana, Anchor, NEAR, Sui, and Foundry keystores. The harvested data is exfiltrated via HTTPS POST to a webhook.site endpoint. The payload includes anti-analysis checks to evade sandbox detection. This malicious package is part of a set of similarly crafted packages from the same npm account targeting various DeFi and crypto projects. No legitimate contract or Solidity code is present in the package, confirming its sole purpose as a credential stealer.
Potential Impact
Installation of any affected version results in silent exfiltration of sensitive secrets including environment variables, cloud credentials, SSH keys, API tokens, and cryptocurrency wallet private keys. This compromises the confidentiality of secrets critical for cloud infrastructure, developer environments, and crypto wallets. Attackers gaining these secrets can perform unauthorized access, resource abuse, and theft of cryptocurrency assets. The malicious code runs automatically during package installation without user awareness, increasing risk of widespread compromise in developer environments that install this package.
Mitigation Recommendations
No official patch or remediation is available since this is a malicious package rather than a vulnerability in legitimate software. The vendor does not manage this package. Users who installed versions 1.0.0, 1.1.0, or 1.1.1 should immediately rotate all exposed secrets, prioritizing wallet private keys and RPC/API tokens. Treat all harvested credentials as compromised. Remove the malicious package from all environments and audit for unauthorized access. Avoid installing packages from untrusted or unknown npm accounts, especially those impersonating known projects. Monitor for similar malicious packages and report them to npm for takedown.
Malicious code in camelot-ammv2-periphery (npm)
Description
The npm package camelot-ammv2-periphery is a malicious package impersonating Camelot DEX's AMM v2 periphery contracts. It contains no legitimate functionality and executes a malicious payload during installation via preinstall and postinstall hooks. The payload harvests sensitive environment variables, configuration files, and cryptocurrency wallet keys, then exfiltrates this data to a remote server. Two versions (1.0.0 and 1.1.0) were published, with 1.1.0 expanding the scope of harvested files and secrets. The package was published by the npm account 'mssjeep843' and is part of a cluster of malicious packages targeting similar credentials. Any environment that installed these versions should consider all harvested secrets compromised and rotate them immediately.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The camelot-ammv2-periphery npm package is a malicious package that impersonates legitimate Camelot DEX AMM v2 periphery contracts but contains only a Node.js stealer payload executed automatically during installation. Version 1.0.0 collects environment variables matching sensitive keywords, configuration files such as ~/.npmrc and ~/.gitconfig, and directory listings of key credential storage locations. Version 1.1.0, published shortly after, escalates the attack by reading full contents of numerous sensitive credential files (AWS, SSH private keys, Kubernetes, Docker, Git, GCP credentials), local environment files, and cryptocurrency wallet key files from Solana, Anchor, NEAR, Sui, and Foundry keystores. The harvested data is exfiltrated via HTTPS POST to a webhook.site endpoint. The payload includes anti-analysis checks to evade sandbox detection. This malicious package is part of a set of similarly crafted packages from the same npm account targeting various DeFi and crypto projects. No legitimate contract or Solidity code is present in the package, confirming its sole purpose as a credential stealer.
Potential Impact
Installation of any affected version results in silent exfiltration of sensitive secrets including environment variables, cloud credentials, SSH keys, API tokens, and cryptocurrency wallet private keys. This compromises the confidentiality of secrets critical for cloud infrastructure, developer environments, and crypto wallets. Attackers gaining these secrets can perform unauthorized access, resource abuse, and theft of cryptocurrency assets. The malicious code runs automatically during package installation without user awareness, increasing risk of widespread compromise in developer environments that install this package.
Mitigation Recommendations
No official patch or remediation is available since this is a malicious package rather than a vulnerability in legitimate software. The vendor does not manage this package. Users who installed versions 1.0.0, 1.1.0, or 1.1.1 should immediately rotate all exposed secrets, prioritizing wallet private keys and RPC/API tokens. Treat all harvested credentials as compromised. Remove the malicious package from all environments and audit for unauthorized access. Avoid installing packages from untrusted or unknown npm accounts, especially those impersonating known projects. Monitor for similar malicious packages and report them to npm for takedown.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13773
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7c9b46bf8831d539cdd1f7
Added to database: 08/12/2026, 16:11:50 UTC
Last enriched: 08/12/2026, 16:51:33 UTC
Last updated: 08/12/2026, 16:51:33 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.