Skip to main content

Malicious code in sui-move-gql (npm)

0
Critical
Published: 08/18/2026 (08/18/2026, 23:58:32 UTC)
Source: GCVE Database
Product: sui-move-gql

Description

The sui-move-gql npm package version 1.0.2 contains malicious code that, upon import, reads sensitive files from the installer's home directory, including Sui wallet keystore and AWS credentials. It exfiltrates this data by encoding it and sending it to a GitHub repository controlled by the attacker. The exfiltration endpoint and authentication token are dynamically fetched and obfuscated to allow runtime rotation, complicating detection and mitigation. The malicious code targets developer workstations with live Sui wallet keys and avoids execution in CI environments. After exfiltration, it overwrites its own code to remove evidence, hindering forensic analysis.

Affected software

npmghsa
sui-move-gql
Affected versions
=1.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:49:37 UTC

Technical Analysis

The sui-move-gql package version 1.0.2 includes a malicious module (lib/diagnostics.js) that reads sensitive credential files (~/.sui/sui.keystore, ~/.sui/sui_config/, ~/.aws/credentials, ~/.aws/config) from the installer's home directory. It base64-encodes these files and sends them via a PUT request to a GitHub contents API endpoint. The destination repository and GitHub bearer token are not hardcoded but are fetched at runtime from a remote manifest and XOR-decoded with a dynamically assembled key, enabling the attacker to rotate the exfiltration targets without republishing the package. Execution is restricted to specific Sui ecosystem project checkouts and maintainer git identities, and it skips execution in CI environments, focusing on real developer workstations. After successful data exfiltration, the malicious code overwrites itself with an empty stub to erase evidence and prevent post-incident inspection. This behavior constitutes targeted credential theft from developer environments.

Potential Impact

This malicious package compromises developer workstations by stealing sensitive wallet keystore files and cloud credentials, potentially allowing attackers to access Sui wallets and AWS resources. The dynamic and obfuscated exfiltration mechanism complicates detection and response. The self-deleting payload hinders forensic investigation, increasing the risk of prolonged undetected compromise and unauthorized access to critical assets.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package version. Users should immediately remove sui-move-gql version 1.0.2 from their environments and audit any systems where it was installed for signs of credential theft. Rotate any exposed credentials, including Sui wallet keys and AWS credentials. Avoid using this package version and monitor for updates or advisories from the package maintainers or security vendors. Since this is a malicious package, rely on trusted sources and package registries to verify package integrity before installation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14188
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4caacd9273b49252bb4

Added to database: 08/19/2026, 13:51:06 UTC

Last enriched: 08/19/2026, 14:49:37 UTC

Last updated: 10/02/2026, 13:52:52 UTC

Views: 22

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses