SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Continuation of the flow/surf-lending DeFi cred-exfil campaign (c1655). Sentinel-9.9.9 depconf squat; preinstall node index.js || true exfils env secrets (mnemonic/private-key/blockfrost) to raw C2 2.25.140.71:8443/surflending/npm-confusion (same C2). Companions bodega-sdk/flowdefi verified identical. No-renotify.

Verification Record

The package is marked as malware by OSV: MAL-2026-5804 with source: amazon-inspector

Details

Note: This report is updated by a verification record

flow-lending-sdk@9.9.9Malicious
Verified
Analysed at: 6/15/26, 5:46 PM
Source: -
SHA256:
Confidence: High