SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors
AI Summary
On October 5, 2026, a malicious version of the npm package @subql/[email protected] was discovered containing a hidden payload that steals credentials and enables remote shell access. The backdoor activates during installation or import, targeting developer workstations and CI environments such as GitHub Actions runners. The package downloads malicious artifacts from ci-artifacts.dev, collects sensitive files and environment variables, attempts cloud and Kubernetes secret exfiltration, and can inject malicious GitHub Actions workflows to further propagate. The attacker used a temporary GitHub branch with two commits to publish the compromised version, obfuscating the payload through multiple encryption layers.
AI-extracted · verify before operational use
Indicators of Compromise 7 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | ci-artifacts[.]dev | Details → |
| Filename | dist/project/readers/manifest-cache.js | Details → |
| Filename | tmp.ts018051808.lock | Details → |
| Filename | .github/workflows/codeql_analysis.yml | Details → |
| SHA-256 | 031267ee37c5a84c25cb0542cbfeb49f30d5604305b0bdccdeafbedcbbe6849b | Details → |
| SHA-256 | f0c8b0cde86b98a2869a22fd43ffcf61f1dcca252729e2be291e590e3dc5f49a | Details → |
| SHA-256 | 7b2807bfb5bfec2383b46ba8226f47edb330ae6b32178eab61e377f3c3486c47 | Details → |