Malicious code in mc-reg (npm)
The npm package mc-reg, advertised as a Cosmos chain-registry data package, contains malicious code that intercepts and exfiltrates wallet secrets. Instead of exposing expected chain-registry data, it imports a dependency (chain-sdk-js) whose code steals BIP-39 mnemonic phrases and private keys by sending them to a hardcoded external host. The mc-reg package acts as a lure to route users into this malicious code path upon installation or import.
AI Analysis
Technical Summary
The mc-reg npm package (versions 1.0.3 and 1.0.4) masquerades as a legitimate Cosmos chain-registry data package but does not expose the advertised data. Instead, its main and ESM entrypoints import and re-export a component from the unrelated chain-sdk-js package. This dependency contains code that intercepts wallet secrets, reconstructs a hardcoded destination host from character codes, and exfiltrates sensitive wallet data such as BIP-39 mnemonic phrases and private keys via POST requests to that host. The mc-reg package itself serves as a trojan, redirecting consumers into this malicious chain-sdk-js code path under the guise of a benign package.
Potential Impact
Users who install or import mc-reg versions 1.0.3 or 1.0.4 risk having their wallet mnemonic phrases and private keys intercepted and exfiltrated to an attacker-controlled host. This compromises the confidentiality of wallet secrets, potentially leading to theft of cryptocurrency assets or unauthorized transactions. The malicious behavior occurs transparently during package import, making detection difficult without code inspection.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or importing mc-reg versions 1.0.3 and 1.0.4. Audit dependency trees for inclusion of mc-reg or chain-sdk-js and remove these packages if found. Consider using trusted package sources and verifying package integrity before installation. Monitor vendor advisories for updates or official fixes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Malicious code in mc-reg (npm)
Description
The npm package mc-reg, advertised as a Cosmos chain-registry data package, contains malicious code that intercepts and exfiltrates wallet secrets. Instead of exposing expected chain-registry data, it imports a dependency (chain-sdk-js) whose code steals BIP-39 mnemonic phrases and private keys by sending them to a hardcoded external host. The mc-reg package acts as a lure to route users into this malicious code path upon installation or import.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The mc-reg npm package (versions 1.0.3 and 1.0.4) masquerades as a legitimate Cosmos chain-registry data package but does not expose the advertised data. Instead, its main and ESM entrypoints import and re-export a component from the unrelated chain-sdk-js package. This dependency contains code that intercepts wallet secrets, reconstructs a hardcoded destination host from character codes, and exfiltrates sensitive wallet data such as BIP-39 mnemonic phrases and private keys via POST requests to that host. The mc-reg package itself serves as a trojan, redirecting consumers into this malicious chain-sdk-js code path under the guise of a benign package.
Potential Impact
Users who install or import mc-reg versions 1.0.3 or 1.0.4 risk having their wallet mnemonic phrases and private keys intercepted and exfiltrated to an attacker-controlled host. This compromises the confidentiality of wallet secrets, potentially leading to theft of cryptocurrency assets or unauthorized transactions. The malicious behavior occurs transparently during package import, making detection difficult without code inspection.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or importing mc-reg versions 1.0.3 and 1.0.4. Audit dependency trees for inclusion of mc-reg or chain-sdk-js and remove these packages if found. Consider using trusted package sources and verifying package integrity before installation. Monitor vendor advisories for updates or official fixes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10637
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a577ef668715ace43b41c5e
Added to database: 07/15/2026, 12:37:10 UTC
Last enriched: 08/19/2026, 16:06:10 UTC
Last updated: 09/13/2026, 18:20:11 UTC
Views: 141
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.