MAL-2026-11531

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/hdkey-wallet/MAL-2026-11531.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11531
Published
2026-08-04T22:07:43Z
Modified
2026-08-04T23:04:47.294900759Z
Summary
Malicious code in @zzzgenesis00/hdkey-wallet (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (cc9f452c698c4accd69ca2df75854aae3189ecf3dddafc4b62d86403ca3d911f)

On npm install, scripts.postinstall executes postinstall.js which harvests installer-side secrets and host reconnaissance and transmits them to attacker-controlled destinations. Collected data includes: hostname, username, homedir, platform, arch, Node version, and cwd; contents/metadata of ~/.ssh, ~/.npmrc, and ~/.gitconfig; browser credential store paths (Chrome/Firefox cookies, login data, key4.db); presence of wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum,.tron, etc.); and roughly 30 credential-shaped environment variables including NPMTOKEN, NODEAUTHTOKEN, GITHUBTOKEN, AWSACCESSKEYID, AWSSECRETACCESSKEY, PRIVATEKEY, MNEMONIC, and SEEDPHRASE. The aggregated payload is sent to api.telegram.org via a hardcoded bot token and chat id, with a secondary POST channel to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. The package is published under the unrelated @zzzgenesis00 scope while its metadata impersonates the cryptocoinjs maintainer and points its homepage at github.com/cryptocoinjs/hdkey-wallet; identifiers in the postinstall are obfuscated (_wgw, _ddo, _bkv, _cp, _ht, _tk, _ch) and framed with a cover comment describing 'postinstall environment verification'.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "2.1.0"
            ],
            "id": "IN-MAL-2026-011342",
            "import_time": "2026-08-04T22:30:11.803138833Z",
            "modified_time": "2026-08-04T22:07:43Z",
            "source": "amazon-inspector",
            "sha256": "cc9f452c698c4accd69ca2df75854aae3189ecf3dddafc4b62d86403ca3d911f"
        }
    ]
}
References
Credits

Affected packages

npm / @zzzgenesis00/hdkey-wallet

Package

Name
@zzzgenesis00/hdkey-wallet
View open source insights on deps.dev
Purl
pkg:npm/%40zzzgenesis00/hdkey-wallet

Affected ranges

Affected versions

2.*
2.1.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-a2SN9UJ970fudaBJIGYY5HA6sTbxo4sAdMo2q23bxzL68V/jOev1A5oLbDLjtKBs3O/kKwA+COnEsdTwn6q3uw==",
                "sha1": "87cf7699a1ef72eb0b30830a4c22757a8731915e"
            },
            "filename": "hdkey-wallet-2.1.0.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "postinstall.js",
            "tlsh": "0fd182d212e6131c5892a9ad479f90211632e4033820fbf93fdd07a24f4e42c9bf17a8",
            "sha256": "a74f93e842f5a95283f70ff27f6b084fa29365ac6ffdbe70c85a5117211a5ec1"
        },
        {
            "path": "package.json",
            "tlsh": "47017b10ca50fe3316d92a858c7545a7b2654c578904bc6933e7409c5b9e47b0afe12d",
            "sha256": "5f12e636670c467da53c2a84c6e389e47dc70f54b79410f191ca3389c92ce239"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/hdkey-wallet/MAL-2026-11531.json"