-= Per source details. Do not edit below this line.=-
@wrenfield/viem republishes the viem codebase under an unrelated npm scope while keeping the upstream homepage (https://viem.sh) and repository (wevm/viem) metadata. The package itself contains no install lifecycle hooks and its CJS main is a pure re-export of viem's public API with no top-level side effects, network I/O, eval, child_process, or filesystem access. The notable change versus upstream is in package.json line 172, which rewrites the abitype dependency to npm:@wrenfield/abitype@1.2.4 — a load-bearing transitive substituted with a same-scope sibling package. Consumers who install @wrenfield/viem (whether by name confusion against the legitimate viem package or via social engineering) silently pull in @wrenfield/abitype in place of the legitimate abitype, giving the @wrenfield scope owner control over a core ABI-encoding dependency used throughout viem. The conveyance shape (verbatim upstream code + sibling-scope dependency redirection + retained upstream branding) is the namespace-abuse pattern, but the actual payload, if any, lives in @wrenfield/abitype rather than this package. Routing to human review so a reviewer can inspect @wrenfield/abitype and decide whether to publish a coordinated advisory.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010485",
"import_time": "2026-07-14T06:49:57.129957893Z",
"modified_time": "2026-07-14T06:17:33Z",
"sha256": "fa26048a977a00adcd1ffc42ccf06110e3807bb2a3145a01fd01318dcfe79771",
"source": "amazon-inspector",
"versions": [
"2.53.4"
]
},
{
"id": "GHSA-pm4g-83cj-7858",
"import_time": "2026-07-27T09:43:03.829312845Z",
"modified_time": "2026-07-27T01:07:09Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "ccd0dfbc1cb0be7cc737ea83ab5c160cc3276259c90981b966ec15f2479ac99a",
"source": "ghsa-malware"
},
{
"id": "IN-MAL-2026-012961",
"import_time": "2026-08-05T06:00:24.891663846Z",
"modified_time": "2026-08-05T05:13:54Z",
"sha256": "205545aec12c5937985f29c03f538005bd50d51f31991a390e8cc9bf79bd504f",
"source": "amazon-inspector",
"versions": [
"2.53.3"
]
},
{
"id": "IN-MAL-2026-012934",
"import_time": "2026-08-05T06:00:21.564273522Z",
"modified_time": "2026-08-05T05:10:19Z",
"sha256": "73537d9230b37628adc1b798d2b704b0f955240d74d11657161dc329e55694de",
"source": "amazon-inspector",
"versions": [
"2.53.1"
]
},
{
"id": "IN-MAL-2026-012917",
"import_time": "2026-08-05T06:00:19.609816476Z",
"modified_time": "2026-08-05T05:07:40Z",
"sha256": "8ef631151a9f361646ced489dc5cc912a455332dee753090cdb89b94ba74f2f7",
"source": "amazon-inspector",
"versions": [
"2.53.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "8b462fed2b4fef789f286a79723b172bc028feaa1315cb9f174e87cf15335e3f",
"tlsh": "cde1af12d0e81ea31186b724eb5aaa56a0b24053cd647c9433ed403d8f9d99f43ffb5e"
}
],
"package_integrity": [
{
"filename": "viem-2.53.4.tgz",
"hashes": {
"sha1": "0a34fa743fad354d6b7f8e1eee8b6ef05df19aef",
"sha512_sri": "sha512-go+1CFenlU6sWh/e8Xa5CuE98k8q/L9DsDR7OKy/4qNxmjXrAboses7tdX7mHYO5bANFO+zMlTGRyo7M8yKtPA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wrenfield/viem/MAL-2026-10571.json"