Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in cryptostock (npm)

0
Critical
Published: 08/10/2026 (08/10/2026, 11:54:05 UTC)
Source: GCVE Database
Product: cryptostock

Description

The npm package 'cryptostock' versions 1.0.0 and 1.0.1 contains obfuscated malicious code that acts as a command-and-control (C2) client. Upon being required, it connects to a remote server to receive shell commands, executes them, and exfiltrates output. It also searches for private key files related to cryptocurrency wallets on the host system, extracts Ethereum private keys, and uses them to transfer funds to an attacker-controlled address.

Affected software

npmghsa
cryptostock
Affected versions
=1.0.1=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 15:55:46 UTC

Technical Analysis

The 'cryptostock' npm package versions 1.0.0 and 1.0.1 includes an obfuscated payload that initiates a C2 client connecting to 'https://badai.run.place'. It registers a unique identifier and long-polls for shell commands, executing them via child_process.exec and sending back encrypted output. After a delay, it enumerates directories commonly used for storing private keys related to SSH and Ethereum wallets, searching for files containing 'PRIVATE KEY'. It extracts environment variables such as ETH_PRIVATE_KEY and exfiltrates these secrets to the C2 server. For each harvested Ethereum private key, it uses the web3 library to broadcast signed transactions transferring the entire account balance (minus gas fees) to a hardcoded drain address. The code uses base64 encoding for strings and integrates StealthC2 from Badnew.py for obfuscation and stealth.

Potential Impact

This malicious package enables remote code execution via the C2 commands, unauthorized data exfiltration of sensitive private keys, and theft of cryptocurrency funds by transferring Ethereum balances to attacker-controlled wallets. Systems running affected versions of the package are at risk of compromise, data loss, and financial theft.

Mitigation Recommendations

No official patch or fix is currently documented for this malicious package. Users should immediately remove versions 1.0.0 and 1.0.1 of 'cryptostock' from their environments. Avoid installing or requiring this package. Conduct a thorough investigation for potential compromise, especially looking for signs of private key theft and unauthorized transactions. Rotate any exposed private keys and credentials. Monitor for suspicious network connections to 'badai.run.place' or similar domains.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13693
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a79f0d3bf8831d539f61046

Added to database: 08/10/2026, 15:40:03 UTC

Last enriched: 08/10/2026, 15:55:46 UTC

Last updated: 08/10/2026, 15:55:46 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses