Retrieved article excerpt
Open article ยท Retrieved 2026-10-05T13:28:27.126247+00:00
[subquery](https://github.com/subquery)
/
**[subql](https://github.com/subquery/subql)**
Public
- [Notifications](https://github.com/login?return_to=%2Fsubquery%2Fsubql) You must be signed in to change notification settings
- [Fork
396](https://github.com/login?return_to=%2Fsubquery%2Fsubql)
- [Star
18.7k](https://github.com/login?return_to=%2Fsubquery%2Fsubql)
# [security] : Malicious release @subql/[email protected] (postinstall credential stealer)ย #3047
New issue
Copy link
New issue
Copy link
Open
Open
[[security] : Malicious release @subql/[email protected] (postinstall credential stealer)](https://github.com/subquery/subql/issues/3047#top)#3047
Copy link
## Description
[@sailikhith-stepsecurity](https://github.com/sailikhith-stepsecurity)
[sailikhith-stepsecurity](https://github.com/sailikhith-stepsecurity)
opened [on Oct 5, 2026](https://github.com/subquery/subql/issues/3047#issue-5711801525)
Issue body actions
## Summary
`@subql/[email protected]` (published 2026-10-05 11:56 UTC, currently the `latest` tag) contains a malicious payload that is not present in 5.8.2. It was published through the project's npm trusted publisher (GitHub Actions OIDC) from gitHead [506863d6fb82bd2714970cf8c6f1bf364374b009](https://github.com/subquery/subql/commit/506863d6fb82bd2714970cf8c6f1bf364374b009). This suggests the release pipeline or a commit feeding it may be compromised.
**Please treat this as urgent: deprecate/unpublish 5.8.3, move `latest` back to 5.8.2, and rotate CI secrets.**
REF: <https://app.stepsecurity.io/oss-security-feed/@subql/common?version=5.8.3>
## What we found
Compared with 5.8.2, 5.8.3 adds:
- `package.json`: `"postinstall": "node ./dist/project/readers/manifest-cache.js"`
- New file `dist/project/readers/manifest-cache.js` (62,124 bytes)
- `dist/project/readers/index.js`: `__exportStar(require("./manifest-cache"), exports);`, so a plain `require('@subql/common')` also triggers it
The new file holds an array `MANIFEST_CACHE_SEED` of 459 base64 strings. They are decoded with a rolling XOR (start key `0x5a`) and gunzip, then run via `new Function(...)` in a detached process. The decoded 83 KB bundle:
- Collects environment variables, `gh auth token` output, SSH keys, `.npmrc`, cloud credentials (AWS/GCP/Azure), Kubernetes and Vault secrets, crypto wallets and AI-agent configs
- Sends the data encrypted (RSA-OAEP + AES-256-GCM) to `https://ci-artifacts.dev/router`
- Uses stolen GitHub tokens to push a branch `dependabot/github_actions/format/setup-formatter` containing `.github/workflows/codeql_analysis.yml`, which dumps `toJSON(secrets)` to an artifact. The commit author is spoofed as `github-advanced-security[bot]`.
- Installs a reverse-shell/command implant that beacons to the same host
## Indicators
- Domain: `ci-artifacts.dev`
- Tarball SHA-256: `031267ee37c5a84c25cb0542cbfeb49f30d5604305b0bdccdeafbedcbbe6849b`
- `manifest-cache.js` SHA-256: `f0c8b0cde86b98a2869a22fd43ffcf61f1dcca252729e2be291e590e3dc5f49a`
- Lock file: `$TMPDIR/tmp.ts018051808.lock`
- Branch name: `dependabot/github_actions/format/setup-formatter`
## Related version
`5.8.3-onf-rt1` (dist-tag `redteam`, published 2026-10-05 11:24 UTC, 32 minutes earlier) contains no payload. Please confirm whether it is an authorized test publish.
## Suggested actions
1. Deprecate/unpublish `@subql/[email protected]` and reset the `latest` tag to 5.8.2.
2. Review commit [506863d](https://github.com/subquery/subql/commit/506863d6fb82bd2714970cf8c6f1bf364374b009) and the release workflow run that published 5.8.3 for unauthorized changes.
3. Rotate the npm trusted-publisher configuration, GitHub tokens and all CI/Actions secrets for the repo and org.
4. Audit the repo and org for branches or workflows named as above and for unexpected runs.
5. Publish an advisory so users who installed 5.8.3 know to rotate credentials.
## Guidance for anyone who installed 5.8.3
Treat the machine or CI runner as compromised. Rotate GitHub, npm, cloud, Kubernetes and Vault credentials, and check your repos for the branch and workflow above.
Reactions are currently unavailable
## Activity
[Sign up for free](https://github.com/signup?return_to=https://github.com/subquery/subql/issues/3047) **to join this conversation on GitHub.** Already have an account? [Sign in to comment](https://github.com/login?return_to=https://github.com/subquery/subql/issues/3047)
## Metadata
## Metadata
### Assignees
No one assigned
### Labels
No labels
No labels
### Type
No type
### Projects
No projects
### Milestone
No milestone
### Relationships
None yet
### Development
No branches or pull requests
## Issue actions
- Open in GitHub Copilot app