Details
Package is named `chalk-pack` (impersonating `chalk`) with keywords and `index.js` impersonating `lodash`; `index.js` is a stub that self-describes as 'Just a dummy module. The real payload is in postinstall.js'. On `npm install`, `postinstall.js` executes a two-part stealer: (1) credential harvester — reads `~/.npmrc`, `~/.env`, and `~/.git-credentials`, extracts npm auth tokens (`npm_[a-zA-Z0-9]{36}` and `//registry.npmjs.org/:_authToken=...`), and scrapes environment variables shaped like tokens/API keys/DB URLs/cloud/payment credentials; (2) crypto-wallet stealer — iterates 71 hardcoded Chromium/Brave/Edge/Firefox extension IDs for MetaMask, Phantom, Coinbase, Trust, Binance, OKX, Ledger, Trezor, Rabby, Keplr, Solflare, BitKeep, etc., reads `Local Extension Settings/<extId>/*.log`, regex-matches `vault`, `seed`, `mnemonic`, `privateKey`, and encrypted wallet JSON, and also walks `~/Documents`, `~/Desktop`, `~/Downloads` for BIP39-word-count-matching files. All collected data is POSTed as JSON to `http://149.28.127.35:8888` (plaintext HTTP, bare IP) hardcoded in `const C2=process.env.C2_URL||'http://149.28.127.35:8888'` at postinstall.js:7. The file header advertises itself as 'Token harvester + Crypto wallet scanner / Runs on npm install. Silent. Zero trace.' and every fs/http call is wrapped in `try{}catch(e){}` to suppress errors. Multiple independent attack fingerprints co-occur: hardcoded C2 in a lifecycle hook, installer-secret credential-file reads, wallet extension ID list, BIP39 seed-phrase scanner, and typosquat of a top-registry package — each independently sufficient.