@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence
A malicious version of the @velora-dex/sdk npm package (v9.4.1) was published on April 7, 2026, containing injected code in dist/index.js that fires at import time rather than via postinstall hooks. The payload downloads a shell script from a C2 server (89.36.224.5), drops an architecture-specific macOS binary into a path
Table of contents
How the Attack WorksRuntime Validation with StepSecurity Harden-RunnerIndicators of CompromiseAm I Affected?Recovery StepsDefense in Depth: How StepSecurity Protects Against ThisReferenceSort: