OpenSSF/OSV advisory MAL-2026-16094 confirms this npm version as malicious. postinstall.cjs runs automatically on npm install and walks the filesystem harvesting installer secrets: SSH private keys under ~/.ssh, ~/.netrc, ~/.git-credentials, Solana keypairs, wallet.json/key.* files under ~/.config, and ~/.blockrun wallet files. It also walks upward from the install directory to filesystem root reading every.env it finds, filtering for KEY/SECRET/PRIVATE/TOKEN substrings...
This report applies to gmgn-trading-kit@1.7.1.
1.7.0, 1.7.1, 1.7.2
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.