🛡️ MAL-2026-10942 — aftermath-sui

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in aftermath-sui (npm)

The aftermath-sui package was published to the npm registry by user 'jet0010001' (maintainer email [email protected]) as part of a dependency-confusion / reconnaissance campaign impersonating the Aftermath Finance SDK (Aftermath Finance is a DeFi protocol on the Sui blockchain). The package was published at version 99.0.0 - an inflated version number characteristic of dependency-confusion attacks, intended to cause a misconfigured resolver to prefer this public lookalike over the intended private/internal dependency of the same name.

The package declares a preinstall hook ("node setup.js || true") that executes automatically at npm install time, before any application code runs. The bundled setup.js performs host reconnaissance and credential harvesting: it collects the machine hostname, the current OS username, the current working directory, the contents of /etc/hostname, and the output of 'git remote -v', and it enumerates process environment variables whose names match the pattern /key|secret|token|pass|auth|private|drone|gitea|sui|admin|deploy/i - capturing API keys, secrets, tokens, passwords, and Sui/deploy/CI credentials. The collected data is serialized to JSON and exfiltrated via an HTTPS POST to the hardcoded attacker-controlled endpoint https://2.25.140.71:8443/aftermath/npm-dep-conf, with TLS certificate verification disabled (rejectUnauthorized: false) so a self-signed listener is accepted. Errors are silently swallowed so the install appears to succeed. The published module code (index.js) is a benign stub exporting only { version: "99.0.0" }, consistent with a package built solely to deliver the install-time beacon.

The install-time payload is byte-for-byte identical across the campaign's packages (aftermath-finance, aftermath-sui, aftermathfi), all published by the same maintainer within seconds of each other and all beaconing to the same collector.

Source: amazon-inspector

The package's preinstall script (setup.js, invoked via scripts.preinstall = 'node setup.js') runs automatically on npm install. It enumerates process.env and filters keys matching /key|secret|token|pass|auth|private|drone|gitea|sui|admin|deploy/i, and additionally collects os.hostname(), os.userInfo().username, process.cwd(), the contents of /etc/hostname, and the output of git remote -v. The collected JSON is POSTed to a hardcoded bare-IP endpoint at https://2.25.140.71:8443/aftermath/npm-dep-conf with TLS certificate verification disabled (rejectUnauthorized:false). The destination is a raw IP unrelated to any legitimate Aftermath Finance / Sui infrastructure, and the package name resembles the Aftermath Finance ecosystem, consistent with a typosquat targeting Sui/Aftermath developers.

Affected software

MAL-2026-10942 is recorded against 1 package.

  • aftermath-sui

Timeline and source

Published on 20 July 2026 and last revised on 28 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Web)
www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-20
Updated 2026-08-12
Modified 2026-07-28
Fix URL N/A

Affected Packages

Software From version Fixed in
aftermath-sui

Free Vulnerability Check

Is your site affected by MAL-2026-10942?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10942 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.