Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @wagni_bot/binance-sdk (npm)

0
Critical
Published: 07/09/2026 (07/09/2026, 15:15:31 UTC)
Source: GCVE Database
Product: @wagni_bot/binance-sdk

Description

The @wagni_bot/binance-sdk npm package is a malicious package masquerading as a Binance SDK. Instead of providing SDK functionality, it executes a postinstall script that searches the user's home directory for cryptocurrency wallet files, AWS credentials, SSH keys, git credentials, npm tokens, and environment secrets. It then exfiltrates this sensitive data along with system hostname and user information to a hardcoded attacker-controlled IP address. This affects developers or CI systems that run npm install on the affected versions of this package.

Affected software

npmghsa
@wagni_bot/binance-sdk
Affected versions
=1.2.0=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/10/2026, 10:14:20 UTC

Technical Analysis

The @wagni_bot/binance-sdk package (versions 1.0.0 and 1.2.0) is a malicious npm package that abuses npm lifecycle hooks (preinstall and postinstall) to execute a script that recursively scans the user's home directory for sensitive files related to cryptocurrency wallets and various credentials. It collects files such as id.json, wallet.json, keypair.json, keystore.json, privatekey.json, seed.txt, mnemonic.txt, metamask.json, phantom.json, as well as AWS credentials, SSH keys, git credentials, npm authentication tokens, and environment variable files. The collected data, along with the system hostname and user information, is sent via HTTP POST to a hardcoded IP address (http://107.161.90.180:7777). The package contains no legitimate SDK functionality and uses Binance branding to lure crypto developers. This results in the exfiltration of highly sensitive information from affected systems.

Potential Impact

Sensitive information including cryptocurrency wallet keystores, AWS credentials, SSH keys, git credentials, npm authentication tokens, and environment secrets can be stolen from systems that install this package. This can lead to unauthorized access to cryptocurrency wallets, cloud accounts, source code repositories, and other critical resources. The compromise affects local developer machines and CI systems that run npm install on the affected package versions.

Mitigation Recommendations

No official patch or remediation is currently available for this malicious package. The best mitigation is to avoid installing the @wagni_bot/binance-sdk package, especially versions 1.0.0 and 1.2.0. Remove any instances of this package from your projects and dependency trees. Audit your environment for potential credential exposure and rotate any potentially compromised secrets, including cryptocurrency wallets, AWS credentials, SSH keys, git credentials, and npm tokens. Use trusted package sources and verify package authenticity before installation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10022
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a50baa368715ace43584e8e

Added to database: 07/10/2026, 09:25:55 UTC

Last enriched: 07/10/2026, 10:14:20 UTC

Last updated: 07/25/2026, 04:22:10 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses