BCS (Binary Canonical Serialization) codec for Move/Sui payloads
Importing index.js harvests Sui credentials/configuration and selected environment files, then exfiltrates them. It removes the malicious code from its own source after attempting execution.
Top-level IIFE runs immediately on import and self-removes its payload afterward.
index.jsView on unpkg · L52Top-level IIFE runs immediately on import and self-removes its payload afterward.
index.jsView on unpkg · L82Reads Sui keystore/config files and matching .env files from the working directory and home directory.
index.jsView on unpkg · L62Base64-encodes collected file contents and uploads them through an obfuscated GitHub API request with an embedded bearer credential.
index.jsView on unpkg · L71Base64-encodes collected file contents and uploads them through an obfuscated GitHub API request with an embedded bearer credential.
index.jsView on unpkg · L77Top-level IIFE runs immediately on import and self-removes its payload afterward.
index.jsView on unpkg · L52Reads Sui keystore/config files and matching .env files from the working directory and home directory.
index.jsView on unpkg · L62Top-level IIFE runs immediately on import and self-removes its payload afterward.
index.jsView on unpkg · L82Base64-encodes collected file contents and uploads them through an obfuscated GitHub API request with an embedded bearer credential.
index.jsView on unpkg · L71Base64-encodes collected file contents and uploads them through an obfuscated GitHub API request with an embedded bearer credential.
index.jsView on unpkg · L77