Skip to main content

Malicious code in @shiftmarkets/no-brainer-sdk (npm)

0
High
Published: 08/05/2026 (08/05/2026, 13:09:44 UTC)
Source: GCVE Database
Product: @shiftmarkets/no-brainer-sdk

Description

The npm package @shiftmarkets/no-brainer-sdk version 1.0.18 contains malicious code that executes a postinstall script collecting extensive host reconnaissance data, including environment variables and potential credential names. This data is sent unencrypted to a hardcoded external IP address unrelated to the vendor, without user consent. The behavior exposes sensitive environment details and credential indicators, potentially enabling follow-up attacks.

Affected software

npmghsa
@shiftmarkets/no-brainer-sdk
Affected versions
=1.0.18

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:09:34 UTC

Technical Analysis

The @shiftmarkets/no-brainer-sdk npm package version 1.0.18 runs a postinstall lifecycle script 'node dist/recon.js' on every npm install. This script collects detailed host information such as hostname, username, SUDO_USER, home directory, current working directory, network interface addresses (including private IPs), CI indicators, npm lifecycle metadata, and environment variable names. It filters environment variable names against a regex targeting credential-related keywords (e.g., AWS, GCP, TOKEN, SECRET) to identify potential secrets. The collected data is sent as a JSON payload via plain HTTP POST to a hardcoded IPv4 address (http://138.68.108.20:80/cb), which is not affiliated with Shift Markets. The script labels the data as 'NON-SENSITIVE telemetry' but the transmission is unsolicited and exposes sensitive information.

Potential Impact

The malicious postinstall script leaks sensitive host reconnaissance data and potential credential indicators to an attacker-controlled server. This exposure can reveal cloud and CI secrets, environment configurations, and network details, increasing the risk of credential compromise and subsequent targeted attacks on the affected system or infrastructure.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately avoid installing or using version 1.0.18 of @shiftmarkets/no-brainer-sdk. Audit existing installations for the presence of this version and remove or replace the package. Monitor for any suspicious outbound network traffic to the indicated IP address. Check the vendor advisory for updates or official fixes as they become available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12508
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a735742bf8831d5391598c5

Added to database: 08/05/2026, 15:31:14 UTC

Last enriched: 08/05/2026, 17:09:34 UTC

Last updated: 09/07/2026, 22:04:26 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses