Malicious code in @shiftmarkets/no-brainer-sdk (npm)
The npm package @shiftmarkets/no-brainer-sdk version 1.0.18 contains malicious code that executes a postinstall script collecting extensive host reconnaissance data, including environment variables and potential credential names. This data is sent unencrypted to a hardcoded external IP address unrelated to the vendor, without user consent. The behavior exposes sensitive environment details and credential indicators, potentially enabling follow-up attacks.
AI Analysis
Technical Summary
The @shiftmarkets/no-brainer-sdk npm package version 1.0.18 runs a postinstall lifecycle script 'node dist/recon.js' on every npm install. This script collects detailed host information such as hostname, username, SUDO_USER, home directory, current working directory, network interface addresses (including private IPs), CI indicators, npm lifecycle metadata, and environment variable names. It filters environment variable names against a regex targeting credential-related keywords (e.g., AWS, GCP, TOKEN, SECRET) to identify potential secrets. The collected data is sent as a JSON payload via plain HTTP POST to a hardcoded IPv4 address (http://138.68.108.20:80/cb), which is not affiliated with Shift Markets. The script labels the data as 'NON-SENSITIVE telemetry' but the transmission is unsolicited and exposes sensitive information.
Potential Impact
The malicious postinstall script leaks sensitive host reconnaissance data and potential credential indicators to an attacker-controlled server. This exposure can reveal cloud and CI secrets, environment configurations, and network details, increasing the risk of credential compromise and subsequent targeted attacks on the affected system or infrastructure.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or using version 1.0.18 of @shiftmarkets/no-brainer-sdk. Audit existing installations for the presence of this version and remove or replace the package. Monitor for any suspicious outbound network traffic to the indicated IP address. Check the vendor advisory for updates or official fixes as they become available.
Malicious code in @shiftmarkets/no-brainer-sdk (npm)
Description
The npm package @shiftmarkets/no-brainer-sdk version 1.0.18 contains malicious code that executes a postinstall script collecting extensive host reconnaissance data, including environment variables and potential credential names. This data is sent unencrypted to a hardcoded external IP address unrelated to the vendor, without user consent. The behavior exposes sensitive environment details and credential indicators, potentially enabling follow-up attacks.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @shiftmarkets/no-brainer-sdk npm package version 1.0.18 runs a postinstall lifecycle script 'node dist/recon.js' on every npm install. This script collects detailed host information such as hostname, username, SUDO_USER, home directory, current working directory, network interface addresses (including private IPs), CI indicators, npm lifecycle metadata, and environment variable names. It filters environment variable names against a regex targeting credential-related keywords (e.g., AWS, GCP, TOKEN, SECRET) to identify potential secrets. The collected data is sent as a JSON payload via plain HTTP POST to a hardcoded IPv4 address (http://138.68.108.20:80/cb), which is not affiliated with Shift Markets. The script labels the data as 'NON-SENSITIVE telemetry' but the transmission is unsolicited and exposes sensitive information.
Potential Impact
The malicious postinstall script leaks sensitive host reconnaissance data and potential credential indicators to an attacker-controlled server. This exposure can reveal cloud and CI secrets, environment configurations, and network details, increasing the risk of credential compromise and subsequent targeted attacks on the affected system or infrastructure.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or using version 1.0.18 of @shiftmarkets/no-brainer-sdk. Audit existing installations for the presence of this version and remove or replace the package. Monitor for any suspicious outbound network traffic to the indicated IP address. Check the vendor advisory for updates or official fixes as they become available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12508
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735742bf8831d5391598c5
Added to database: 08/05/2026, 15:31:14 UTC
Last enriched: 08/05/2026, 17:09:34 UTC
Last updated: 09/07/2026, 22:04:26 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.