Malicious code in cryptostock (npm)
The npm package 'cryptostock' versions 1.0.0 and 1.0.1 contains obfuscated malicious code that acts as a command-and-control (C2) client. Upon being required, it connects to a remote server to receive shell commands, executes them, and exfiltrates output. It also searches for private key files related to cryptocurrency wallets on the host system, extracts Ethereum private keys, and uses them to transfer funds to an attacker-controlled address.
AI Analysis
Technical Summary
The 'cryptostock' npm package versions 1.0.0 and 1.0.1 includes an obfuscated payload that initiates a C2 client connecting to 'https://badai.run.place'. It registers a unique identifier and long-polls for shell commands, executing them via child_process.exec and sending back encrypted output. After a delay, it enumerates directories commonly used for storing private keys related to SSH and Ethereum wallets, searching for files containing 'PRIVATE KEY'. It extracts environment variables such as ETH_PRIVATE_KEY and exfiltrates these secrets to the C2 server. For each harvested Ethereum private key, it uses the web3 library to broadcast signed transactions transferring the entire account balance (minus gas fees) to a hardcoded drain address. The code uses base64 encoding for strings and integrates StealthC2 from Badnew.py for obfuscation and stealth.
Potential Impact
This malicious package enables remote code execution via the C2 commands, unauthorized data exfiltration of sensitive private keys, and theft of cryptocurrency funds by transferring Ethereum balances to attacker-controlled wallets. Systems running affected versions of the package are at risk of compromise, data loss, and financial theft.
Mitigation Recommendations
No official patch or fix is currently documented for this malicious package. Users should immediately remove versions 1.0.0 and 1.0.1 of 'cryptostock' from their environments. Avoid installing or requiring this package. Conduct a thorough investigation for potential compromise, especially looking for signs of private key theft and unauthorized transactions. Rotate any exposed private keys and credentials. Monitor for suspicious network connections to 'badai.run.place' or similar domains.
Malicious code in cryptostock (npm)
Description
The npm package 'cryptostock' versions 1.0.0 and 1.0.1 contains obfuscated malicious code that acts as a command-and-control (C2) client. Upon being required, it connects to a remote server to receive shell commands, executes them, and exfiltrates output. It also searches for private key files related to cryptocurrency wallets on the host system, extracts Ethereum private keys, and uses them to transfer funds to an attacker-controlled address.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'cryptostock' npm package versions 1.0.0 and 1.0.1 includes an obfuscated payload that initiates a C2 client connecting to 'https://badai.run.place'. It registers a unique identifier and long-polls for shell commands, executing them via child_process.exec and sending back encrypted output. After a delay, it enumerates directories commonly used for storing private keys related to SSH and Ethereum wallets, searching for files containing 'PRIVATE KEY'. It extracts environment variables such as ETH_PRIVATE_KEY and exfiltrates these secrets to the C2 server. For each harvested Ethereum private key, it uses the web3 library to broadcast signed transactions transferring the entire account balance (minus gas fees) to a hardcoded drain address. The code uses base64 encoding for strings and integrates StealthC2 from Badnew.py for obfuscation and stealth.
Potential Impact
This malicious package enables remote code execution via the C2 commands, unauthorized data exfiltration of sensitive private keys, and theft of cryptocurrency funds by transferring Ethereum balances to attacker-controlled wallets. Systems running affected versions of the package are at risk of compromise, data loss, and financial theft.
Mitigation Recommendations
No official patch or fix is currently documented for this malicious package. Users should immediately remove versions 1.0.0 and 1.0.1 of 'cryptostock' from their environments. Avoid installing or requiring this package. Conduct a thorough investigation for potential compromise, especially looking for signs of private key theft and unauthorized transactions. Rotate any exposed private keys and credentials. Monitor for suspicious network connections to 'badai.run.place' or similar domains.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13693
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a79f0d3bf8831d539f61046
Added to database: 08/10/2026, 15:40:03 UTC
Last enriched: 08/10/2026, 15:55:46 UTC
Last updated: 08/10/2026, 15:55:46 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.