StepSecurity flagged a malicious release of @subql/[email protected], a core package of the SubQuery blockchain data-indexing toolchain, published to npm on October 5, 2026 at 11:56 UTC. The release carries a hidden payload that harvests developer and CI credentials, supports remote shell access, and uses stolen GitHub tokens to persist in victims’ repositories. Version 5.8.2 is clean.
What Happened
Roughly 32 minutes before the malicious release, a suspicious 5.8.3-onf-rt1 build appeared under a redteam dist-tag (11:24 UTC), which looks like staging or testing of the publish path. The actual 5.8.3 release was then pushed as latest. A GitHub issue (subquery/subql #3047) opened by StepSecurity asks maintainers to unpublish it, revert latest to 5.8.2, and audit commit 506863d and the associated CI/CD runs, which points at a release-pipeline or trusted-publisher compromise rather than a typosquat. At the time of reporting, no maintainer response had been documented.
Technical Details
- Execution:
package.jsongains apostinstallhook running./dist/project/readers/manifest-cache.js(about 62 KB). The file holds 459 base64 strings, decoded with a rolling XOR (seed0x5a) plus gunzip into an ~83 KB payload executed vianew Function(). - Import-time trigger: The payload also fires when the package is imported, so installing with
--ignore-scriptsis not sufficient protection. - Collection: Environment variables,
gh auth tokenoutput, SSH keys,.npmrc, AWS/GCP/Azure credentials, Kubernetes and Vault secrets, crypto wallets, and AI-agent configuration files. - Exfiltration: Data is encrypted with RSA-OAEP and AES-256-GCM and posted to
https://ci-artifacts.dev/router. - Persistence: Using stolen GitHub tokens, the implant pushes spoofed commits on a branch named
dependabot/github_actions/format/setup-formatterthat add.github/workflows/codeql_analysis.yml, a workflow dressed up as CodeQL scanning that gives the attacker a foothold in CI. - Remote access: A reverse-shell implant beacons to the same infrastructure. A lock file at
$TMPDIR/tmp.ts018051808.lockis used for single-instance control.
Impact
Any package that depends on @subql/common with a range admitting 5.8.3 can pull it in. The published manifests for @subql/[email protected] and @subql/[email protected] declare @subql/common ~5.8.2, so fresh installs without a lockfile would resolve to the malicious version. Developer workstations and CI runners (notably GitHub Actions) that installed or imported it should be considered fully compromised. Stolen cloud and Kubernetes credentials make lateral movement into production likely, and the worm-like use of GitHub tokens means downstream repositories may now host attacker-controlled workflows.
Mitigation
- Pin
@subql/commonto 5.8.2 (usenpm ls @subql/commonand lockfile review) and block 5.8.3 in your registry proxy. - Search CI logs, build caches and developer machines for 5.8.3 installs after 11:56 UTC on October 5.
- On any exposed host, rotate GitHub, npm, SSH, AWS/GCP/Azure, Kubernetes service-account and Vault credentials. Rotate from a clean machine.
- Search your GitHub organizations for the
dependabot/github_actions/format/setup-formatterbranch and any unexpectedcodeql_analysis.yml; review recent workflow runs and token usage in audit logs. - Block
ci-artifacts.devat DNS and egress, and hunt for the lock file path above. - Maintainers: unpublish 5.8.3, restore the
latesttag, rotate npm trusted-publisher configuration and all organization secrets, and issue an advisory.