www.stepsecurity.io 5 Oct 2026, 12:59 UTC

Malicious SubQuery npm Release Steals Credentials and Opens Remote Shells

CyberSIXT Evidence Panel Source marked as original reporting

ON 5 October 2026, StepSecurity flagged @subql/common@5.8.3 on npm as suspicious and confirmed a hidden payload that harvests credentials and enables remote shell access. The payload triggers during installation and on import, targeting developer workstations and CI environments, including GitHub Actions runners and accessible cloud services. Investigations involved downloading the tarball, validating SHA-512 against npm metadata, and tracing repository changes.

Key evidence includes two short‑lived branch lifecycles, a canary publish workflow that repackaged 5.8.2 as 5.8.3-onf-rt1, an external artifact substitution in the final release workflow, and an npm provenance record tied to a now‑unavailable Actions run identifier. The recommendation is to treat 5.8.3 as unsafe, block ci-artifacts[.]dev, and investigate any systems where this version ran; disabling install scripts alone is insufficient because the payload also starts on import. A GitHub issue has been opened (SubQuery repository #3047) to solicit maintainer investigation.

The article details how @subql/common is a shared library within the SubQuery Web3 data‑indexing framework, and explains that the 5.8.3 release introduced complex multi‑layered payload delivery. Evidence shows the harm could propagate to ecosystems using dependent packages, given that parent packages may resolve to 5.8.3 via version ranges.

The exposed capabilities range from credential collection (including .npmrc, env, AWS, SSH keys, and cloud secrets) to remote command execution and exfiltration via an encrypted envelope to ci-artifacts[.]dev, with a dedicated command and shell channel at /shell. Immediate remediation steps include excluding 5.8.3 from dependency resolution, isolating affected hosts, rotating credentials, and hunting for indicators tied to ci-artifacts[.]dev and the loader or workflow artifacts.

View full article

Article by CyberSIXT