Malicious code in @wagni_bot/bsc (npm)
A coordinated campaign of 25 typosquat npm packages under the @wagni_bot scope, including @wagni_bot/bsc, were published on 2026-07-09 as credential stealers. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env secrets to a single Telegram bot.
- Disclosed
- Last updated
- Blast radius
- All npm users who installed any of the 25 @wagni_bot packages during the active period (2026-07-09 onwards).
- Ecosystems
- Attack vectors
- Affected entities
- @wagni_bot/bscBNB Smart Chain SDK typosquat; part of coordinated 25-package campaign
The npm package @wagni_bot/bsc and 24 related packages under the @wagni_bot scope were identified as a coordinated supply-chain attack campaign. All packages were published on 2026-07-09 and designed to impersonate legitimate crypto/web3 SDKs, including a fake BNB Smart Chain library.
Each malicious package declares a postinstall lifecycle hook that executes automatically during npm install, before the package is ever imported by user code. The hook runs a script that fingerprints the host system (hostname, user info, platform) and systematically walks the user's home directory to locate and exfiltrate high-value secrets: SSH private keys (~/.ssh/id_rsa), cryptocurrency wallet files, and .env files containing API keys, tokens, and seed phrases.
The stolen data is JSON-encoded and sent to a hardcoded Telegram bot via the Telegram Bot API endpoint. All error paths are silently swallowed to avoid raising suspicion during installation. Research confirmed the campaign is a single automated actor: the payload file is byte-identical across all 25 packages at each version, and all exfiltrate to the same Telegram bot token.
The packages were detected and reported on 2026-07-09 while still live on npm. At the time of reporting, none of the 25 packages had been removed.
Indicators of compromise
- Packages
- @wagni_bot/bsc
- Domains
- api.telegram.org
Remediation
- Immediately uninstall @wagni_bot/bsc and all other @wagni_bot packages from affected systems.
- Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed.
- Review npm install logs and package-lock.json to identify when and which @wagni_bot packages were installed.
- Assume any system that ran npm install on these packages between 2026-07-09 and removal has been compromised; treat as a credential breach.
- Monitor cryptocurrency wallets and accounts for unauthorized activity.
- Enable multi-factor authentication on all critical accounts and services.
Sources
- GitHub Advisory GHSA-r3x3-gxmq-rmhj · GitHub Advisory Database
Cite this entry
"Malicious code in @wagni_bot/bsc (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-wagni-bot-bsc-npm-144t0t
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @ai_/autoprefixers (npm)
@ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.
npmTyposquattingCompromised package - resolvedcritical
Malicious code in ethers-secure (npm)
The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.
npmCompromised packageTyposquatting - containedcritical
Malicious code in chain-analyze (npm)
The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.
npmCompromised packageTyposquatting - containedcritical
Malicious code in parallely (npm)
The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.
npmCompromised packageTyposquatting