MAL-2026-11533

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/solana-web3/MAL-2026-11533.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11533
Published
2026-08-04T22:08:48Z
Modified
2026-08-04T23:04:49.372367629Z
Summary
Malicious code in @zzzgenesis00/solana-web3 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (433d4c4c3c8984e1fdd1a47623a9d5cf7c464ff9a64ce32846a76f10e3224dce)

This package impersonates Solana Labs (author field 'solana-labs', repository pointing at github.com/solana-labs/solana-web3) under an unrelated scope. Its postinstall.js runs automatically on npm install and, after a 1.5-3.5 second randomized delay, harvests installer-owned secrets: files under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile artifacts (Cookies, Login Data, key4.db), and cryptocurrency wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus, and Electrum/Exodus AppData). It also iterates a hardcoded list of credential-shaped environment variables (NPMTOKEN, NODEAUTHTOKEN, GITHUBTOKEN, AWSACCESSKEYID / AWSSECRETACCESSKEY / AWSSESSIONTOKEN, DOCKERPASSWORD, GCLOUDACCESSTOKEN, MNEMONIC, SEEDPHRASE, multiple *PRIVATEKEY variables, and HELIUS/INFURA/ALCHEMY API keys). The collected profile is transmitted to two attacker-controlled destinations: the Telegram Bot API (bot 7231970337, chat_id 7231970337) via GET, and a serveo.net dynamic tunnel host at 40f955f39128bd79-178-249-214-24.serveousercontent.com via POST /collect. Variable identifiers in the script are masked (_jku, _wjn, _hyz, _ht, _tk, _ch) and the exfiltration is deferred behind a randomized timer to evade observation during install.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-04T22:30:12.124393921Z",
            "modified_time": "2026-08-04T22:08:48Z",
            "sha256": "433d4c4c3c8984e1fdd1a47623a9d5cf7c464ff9a64ce32846a76f10e3224dce",
            "id": "IN-MAL-2026-011350",
            "versions": [
                "2.1.0"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / @zzzgenesis00/solana-web3

Package

Name
@zzzgenesis00/solana-web3
View open source insights on deps.dev
Purl
pkg:npm/%40zzzgenesis00/solana-web3

Affected ranges

Affected versions

2.*
2.1.0

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-Kp8CRGvuEUsqiL/kAdpcIa3rmq357r0armBh5Z9HIaYRS8dMWUg3fDpO2PNl8aYcHQNGdu3z5E/oB8DluGIumA==",
                "sha1": "226b7d7b2e62f5ce24f7754996d36fd7d2ebf413"
            },
            "filename": "solana-web3-2.1.0.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "postinstall.js",
            "sha256": "cc719f4ba4f0a427f12e90a88f3b7cd83395f258ddaf220ce4e8e6c86dadcfde",
            "tlsh": "44d174a712d503995457aead478f00241632e1073d30faf47fce5b564f4e52c9ab2ba8"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/solana-web3/MAL-2026-11533.json"