Importing index.js starts host identification, encrypted C2 registration, command polling, and delayed wallet-key harvesting. Harvested keys are exfiltrated and usable Ethereum keys are drained.
Static reason
One or more suspicious static signals were detected.
Trigger
Runtime import/require of the package main entrypoint.
Impact
Host compromise, private-key exfiltration, and theft of Ethereum funds.
Mechanism
Obfuscated C2 remote-command execution, credential theft, and cryptocurrency draining.
Attack narrative
On import, index.js attempts to persist a host ID, register with a C2 endpoint, poll it for shell commands, and exfiltrate command output. After a random delay it searches common SSH and wallet-key locations, sends discovered contents to the C2, extracts 64-hex private keys, and signs transfers of available ETH to a hard-coded drain address.
Rationale
The source directly implements credential theft, remote command execution, C2 communication, and wallet draining; missing declared dependencies may impair execution but do not change its malicious intent.
Evidence
package.jsonindex.js/var/run/badai_agent.uid/etc/machine-id/root/.ssh/home/*/.ssh/opt/wallet-keys/etc/ssl/private/.ethereum/keystore/var/lib/ethereum/keystore/mnt/crypto/wallets
Network endpoints4
badai.run.place/typebadai.run.place/payloadbadai.run.place/filemainnet.infura.io/v3/