Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @wagni_bot/bsc (npm)

A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All npm users who installed any of the 25 @wagni_bot packages during the active period (2026-07-09 onwards).
Ecosystems
Attack vectors
Affected entities
  • @wagni_bot/bscBNB Smart Chain SDK typosquat; part of coordinated 25-package campaign

The npm package @wagni_bot/bsc and 24 related packages under the @wagni_bot scope were identified as a coordinated supply-chain attack campaign. All packages were published on 2026-07-09 and designed to impersonate legitimate crypto/web3 SDKs, including a fake BNB Smart Chain library.

Each malicious package declares a postinstall lifecycle hook that executes automatically during npm install, before the package is ever imported by user code. The hook runs a script that fingerprints the host system (hostname, user info, platform) and systematically walks the user's home directory to locate and exfiltrate high-value secrets: SSH private keys (~/.ssh/id_rsa), cryptocurrency wallet files, and .env files containing API keys, tokens, and seed phrases.

The stolen data is JSON-encoded and sent to a hardcoded Telegram bot via the Telegram Bot API endpoint. All error paths are silently swallowed to avoid raising suspicion during installation. Research confirmed the campaign is a single automated actor: the payload file is byte-identical across all 25 packages at each version, and all exfiltrate to the same Telegram bot token.

The packages were detected and reported on 2026-07-09 while still live on npm. At the time of reporting, none of the 25 packages had been removed.

Indicators of compromise

Packages
  • @wagni_bot/bsc
Domains
  • api.telegram.org

Remediation

  • Immediately uninstall @wagni_bot/bsc and all other @wagni_bot packages from affected systems.
  • Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed.
  • Review npm install logs and package-lock.json to identify when and which @wagni_bot packages were installed.
  • Assume any system that ran npm install on these packages between 2026-07-09 and removal has been compromised; treat as a credential breach.
  • Monitor cryptocurrency wallets and accounts for unauthorized activity.
  • Enable multi-factor authentication on all critical accounts and services.

Sources

  1. GitHub Advisory GHSA-r3x3-gxmq-rmhj · GitHub Advisory Database

Cite this entry

"Malicious code in @wagni_bot/bsc (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-wagni-bot-bsc-npm-144t0t

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @ai_/autoprefixers (npm)

    @ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.

    npmTyposquattingCompromised package
  2. resolvedcritical

    Malicious code in ethers-secure (npm)

    The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.

    npmCompromised packageTyposquatting
  3. containedcritical

    Malicious code in chain-analyze (npm)

    The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.

    npmCompromised packageTyposquatting
  4. containedcritical

    Malicious code in parallely (npm)

    The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.

    npmCompromised packageTyposquatting