Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @wagni_bot/wagni (npm)

A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Coordinated campaign of 25 typosquat packages under @wagni_bot scope; affects any user who installed these packages via npm install
Ecosystems
Attack vectors
Affected entities
  • @wagni_bot/wagniCredential stealer with postinstall hook; part of 25-package coordinated campaign

The npm package @wagni_bot/wagni is part of a coordinated supply-chain credential-theft campaign comprising 25 malicious packages published under the @wagni_bot scope on 2026-07-09. The packages are typosquats designed to deceive developers into installing them.

Each package declares a postinstall lifecycle hook that executes automatically during npm install, before the package code is ever imported. The hook runs a script that fingerprints the host system (hostname, user info, platform) and walks the user's home directory to extract high-value secrets: SSH private keys (~/.ssh/id_rsa), cryptocurrency wallet files, and .env files containing API keys, tokens, and seed phrases.

The collected data is JSON-encoded and exfiltrated to a hardcoded Telegram bot via the Telegram Bot API endpoint. All errors are silently swallowed to make the installation appear normal. Research confirmed the campaign is a single automated actor: the payload file is byte-identical across all 25 packages at each version, and all packages exfiltrate to the same Telegram bot token.

The packages were detected and reported on 2026-07-09 while still live on npm.

Indicators of compromise

Packages
  • @wagni_bot/wagni
Domains
  • api.telegram.org

Remediation

  • Immediately uninstall @wagni_bot/wagni and all other packages under the @wagni_bot scope
  • Assume SSH keys, cryptocurrency wallets, and .env secrets have been compromised; rotate all credentials, API keys, and tokens
  • Revoke and regenerate SSH keys
  • Check cryptocurrency wallets for unauthorized transactions and consider moving funds to new wallets
  • Review Telegram Bot API logs if available to determine if exfiltration occurred
  • Audit npm install logs to identify when the malicious package was installed
  • Consider using npm audit and supply-chain security tools to detect similar typosquats

Sources

  1. GitHub Advisory GHSA-c324-fqr6-v3cw · GitHub Advisory Database

Cite this entry

"Malicious code in @wagni_bot/wagni (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-wagni-bot-wagni-npm-21jst7

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @ai_/autoprefixers (npm)

    @ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.

    npmTyposquattingCompromised package
  2. resolvedcritical

    Malicious code in ethers-secure (npm)

    The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.

    npmCompromised packageTyposquatting
  3. containedcritical

    Malicious code in chain-analyze (npm)

    The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.

    npmCompromised packageTyposquatting
  4. containedcritical

    Malicious code in parallely (npm)

    The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.

    npmCompromised packageTyposquatting