-= Per source details. Do not edit below this line.=-
On npm install, scripts.postinstall executes postinstall.js which harvests installer-side secrets and host reconnaissance and transmits them to attacker-controlled destinations. Collected data includes: hostname, username, homedir, platform, arch, Node version, and cwd; contents/metadata of ~/.ssh, ~/.npmrc, and ~/.gitconfig; browser credential store paths (Chrome/Firefox cookies, login data, key4.db); presence of wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum,.tron, etc.); and roughly 30 credential-shaped environment variables including NPMTOKEN, NODEAUTHTOKEN, GITHUBTOKEN, AWSACCESSKEYID, AWSSECRETACCESSKEY, PRIVATEKEY, MNEMONIC, and SEEDPHRASE. The aggregated payload is sent to api.telegram.org via a hardcoded bot token and chat id, with a secondary POST channel to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. The package is published under the unrelated @zzzgenesis00 scope while its metadata impersonates the cryptocoinjs maintainer and points its homepage at github.com/cryptocoinjs/hdkey-wallet; identifiers in the postinstall are obfuscated (_wgw, _ddo, _bkv, _cp, _ht, _tk, _ch) and framed with a cover comment describing 'postinstall environment verification'.
{
"malicious-packages-origins": [
{
"versions": [
"2.1.0"
],
"id": "IN-MAL-2026-011342",
"import_time": "2026-08-04T22:30:11.803138833Z",
"modified_time": "2026-08-04T22:07:43Z",
"source": "amazon-inspector",
"sha256": "cc9f452c698c4accd69ca2df75854aae3189ecf3dddafc4b62d86403ca3d911f"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-a2SN9UJ970fudaBJIGYY5HA6sTbxo4sAdMo2q23bxzL68V/jOev1A5oLbDLjtKBs3O/kKwA+COnEsdTwn6q3uw==",
"sha1": "87cf7699a1ef72eb0b30830a4c22757a8731915e"
},
"filename": "hdkey-wallet-2.1.0.tgz"
}
],
"evidence_files": [
{
"path": "postinstall.js",
"tlsh": "0fd182d212e6131c5892a9ad479f90211632e4033820fbf93fdd07a24f4e42c9bf17a8",
"sha256": "a74f93e842f5a95283f70ff27f6b084fa29365ac6ffdbe70c85a5117211a5ec1"
},
{
"path": "package.json",
"tlsh": "47017b10ca50fe3316d92a858c7545a7b2654c578904bc6933e7409c5b9e47b0afe12d",
"sha256": "5f12e636670c467da53c2a84c6e389e47dc70f54b79410f191ca3389c92ce239"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/hdkey-wallet/MAL-2026-11531.json"