StepSecurity flagged a malicious release of @subql/[email protected], a core package of the SubQuery blockchain data-indexing toolchain, published to npm on October 5, 2026 at 11:56 UTC. The release carries a hidden payload that harvests developer and CI credentials, supports remote shell access, and uses stolen GitHub tokens to persist in victims’ repositories. Version 5.8.2 is clean.

What Happened

Roughly 32 minutes before the malicious release, a suspicious 5.8.3-onf-rt1 build appeared under a redteam dist-tag (11:24 UTC), which looks like staging or testing of the publish path. The actual 5.8.3 release was then pushed as latest. A GitHub issue (subquery/subql #3047) opened by StepSecurity asks maintainers to unpublish it, revert latest to 5.8.2, and audit commit 506863d and the associated CI/CD runs, which points at a release-pipeline or trusted-publisher compromise rather than a typosquat. At the time of reporting, no maintainer response had been documented.

Technical Details

  • Execution: package.json gains a postinstall hook running ./dist/project/readers/manifest-cache.js (about 62 KB). The file holds 459 base64 strings, decoded with a rolling XOR (seed 0x5a) plus gunzip into an ~83 KB payload executed via new Function().
  • Import-time trigger: The payload also fires when the package is imported, so installing with --ignore-scripts is not sufficient protection.
  • Collection: Environment variables, gh auth token output, SSH keys, .npmrc, AWS/GCP/Azure credentials, Kubernetes and Vault secrets, crypto wallets, and AI-agent configuration files.
  • Exfiltration: Data is encrypted with RSA-OAEP and AES-256-GCM and posted to https://ci-artifacts.dev/router.
  • Persistence: Using stolen GitHub tokens, the implant pushes spoofed commits on a branch named dependabot/github_actions/format/setup-formatter that add .github/workflows/codeql_analysis.yml, a workflow dressed up as CodeQL scanning that gives the attacker a foothold in CI.
  • Remote access: A reverse-shell implant beacons to the same infrastructure. A lock file at $TMPDIR/tmp.ts018051808.lock is used for single-instance control.

Impact

Any package that depends on @subql/common with a range admitting 5.8.3 can pull it in. The published manifests for @subql/[email protected] and @subql/[email protected] declare @subql/common ~5.8.2, so fresh installs without a lockfile would resolve to the malicious version. Developer workstations and CI runners (notably GitHub Actions) that installed or imported it should be considered fully compromised. Stolen cloud and Kubernetes credentials make lateral movement into production likely, and the worm-like use of GitHub tokens means downstream repositories may now host attacker-controlled workflows.

Mitigation

  1. Pin @subql/common to 5.8.2 (use npm ls @subql/common and lockfile review) and block 5.8.3 in your registry proxy.
  2. Search CI logs, build caches and developer machines for 5.8.3 installs after 11:56 UTC on October 5.
  3. On any exposed host, rotate GitHub, npm, SSH, AWS/GCP/Azure, Kubernetes service-account and Vault credentials. Rotate from a clean machine.
  4. Search your GitHub organizations for the dependabot/github_actions/format/setup-formatter branch and any unexpected codeql_analysis.yml; review recent workflow runs and token usage in audit logs.
  5. Block ci-artifacts.dev at DNS and egress, and hunt for the lock file path above.
  6. Maintainers: unpublish 5.8.3, restore the latest tag, rotate npm trusted-publisher configuration and all organization secrets, and issue an advisory.

References