logo

Malicious VeloraDEX SDK Compromises Developer Machines via npm

ID: 429af67f-336a-5981-b204-5170caa2980b

STIX ID: report--429af67f-336a-5981-b204-5170caa2980b

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

A malicious update to the @velora-dex/sdk npm package (v9.4.1) was published to the npm registry and contains three injected lines in dist/index.js that execute on require()/import. The injected code contacts C2 89.36.224.5 to download a secondary script that drops a specialized macOS binary into ~/Library/Application Support/com.apple.Terminal/profiler and registers a persistent launchctl service named zsh.profiler; the attacker bypassed the normal CI/CD pipeline and the compromise risks exposure of cloud credentials, tokens, SSH keys, and other secrets. StepSecurity and other researchers recommend pinning to v9.4.0, removing the persistence, auditing network logs for the C2 IP, and rotating all potentially exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.