Malicious code in @wagni_bot/wagni (npm)
A coordinated campaign of 25 malicious npm packages under the @wagni_bot scope, including @wagni_bot/wagni, were published on 2026-07-09 as typosquats. Each package contains a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, .env files, and system fingerprints to a hardcoded Telegram bot.
- Disclosed
- Last updated
- Blast radius
- Coordinated campaign of 25 typosquat packages under @wagni_bot scope; affects any user who installed these packages via npm install
- Ecosystems
- Attack vectors
- Affected entities
- @wagni_bot/wagniCredential stealer with postinstall hook; part of 25-package coordinated campaign
The npm package @wagni_bot/wagni is part of a coordinated supply-chain credential-theft campaign comprising 25 malicious packages published under the @wagni_bot scope on 2026-07-09. The packages are typosquats designed to deceive developers into installing them.
Each package declares a postinstall lifecycle hook that executes automatically during npm install, before the package code is ever imported. The hook runs a script that fingerprints the host system (hostname, user info, platform) and walks the user's home directory to extract high-value secrets: SSH private keys (~/.ssh/id_rsa), cryptocurrency wallet files, and .env files containing API keys, tokens, and seed phrases.
The collected data is JSON-encoded and exfiltrated to a hardcoded Telegram bot via the Telegram Bot API endpoint. All errors are silently swallowed to make the installation appear normal. Research confirmed the campaign is a single automated actor: the payload file is byte-identical across all 25 packages at each version, and all packages exfiltrate to the same Telegram bot token.
The packages were detected and reported on 2026-07-09 while still live on npm.
Indicators of compromise
- Packages
- @wagni_bot/wagni
- Domains
- api.telegram.org
Remediation
- Immediately uninstall @wagni_bot/wagni and all other packages under the @wagni_bot scope
- Assume SSH keys, cryptocurrency wallets, and .env secrets have been compromised; rotate all credentials, API keys, and tokens
- Revoke and regenerate SSH keys
- Check cryptocurrency wallets for unauthorized transactions and consider moving funds to new wallets
- Review Telegram Bot API logs if available to determine if exfiltration occurred
- Audit npm install logs to identify when the malicious package was installed
- Consider using npm audit and supply-chain security tools to detect similar typosquats
Sources
- GitHub Advisory GHSA-c324-fqr6-v3cw · GitHub Advisory Database
Cite this entry
"Malicious code in @wagni_bot/wagni (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-wagni-bot-wagni-npm-21jst7
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @ai_/autoprefixers (npm)
@ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.
npmTyposquattingCompromised package - resolvedcritical
Malicious code in ethers-secure (npm)
The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.
npmCompromised packageTyposquatting - containedcritical
Malicious code in chain-analyze (npm)
The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.
npmCompromised packageTyposquatting - containedcritical
Malicious code in parallely (npm)
The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.
npmCompromised packageTyposquatting