-= Per source details. Do not edit below this line.=-
This package impersonates Solana Labs (author field 'solana-labs', repository pointing at github.com/solana-labs/solana-web3) under an unrelated scope. Its postinstall.js runs automatically on npm install and, after a 1.5-3.5 second randomized delay, harvests installer-owned secrets: files under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile artifacts (Cookies, Login Data, key4.db), and cryptocurrency wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus, and Electrum/Exodus AppData). It also iterates a hardcoded list of credential-shaped environment variables (NPMTOKEN, NODEAUTHTOKEN, GITHUBTOKEN, AWSACCESSKEYID / AWSSECRETACCESSKEY / AWSSESSIONTOKEN, DOCKERPASSWORD, GCLOUDACCESSTOKEN, MNEMONIC, SEEDPHRASE, multiple *PRIVATEKEY variables, and HELIUS/INFURA/ALCHEMY API keys). The collected profile is transmitted to two attacker-controlled destinations: the Telegram Bot API (bot 7231970337, chat_id 7231970337) via GET, and a serveo.net dynamic tunnel host at 40f955f39128bd79-178-249-214-24.serveousercontent.com via POST /collect. Variable identifiers in the script are masked (_jku, _wjn, _hyz, _ht, _tk, _ch) and the exfiltration is deferred behind a randomized timer to evade observation during install.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-04T22:30:12.124393921Z",
"modified_time": "2026-08-04T22:08:48Z",
"sha256": "433d4c4c3c8984e1fdd1a47623a9d5cf7c464ff9a64ce32846a76f10e3224dce",
"id": "IN-MAL-2026-011350",
"versions": [
"2.1.0"
],
"source": "amazon-inspector"
}
]
}[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-Kp8CRGvuEUsqiL/kAdpcIa3rmq357r0armBh5Z9HIaYRS8dMWUg3fDpO2PNl8aYcHQNGdu3z5E/oB8DluGIumA==",
"sha1": "226b7d7b2e62f5ce24f7754996d36fd7d2ebf413"
},
"filename": "solana-web3-2.1.0.tgz"
}
],
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "cc719f4ba4f0a427f12e90a88f3b7cd83395f258ddaf220ce4e8e6c86dadcfde",
"tlsh": "44d174a712d503995457aead478f00241632e1073d30faf47fce5b564f4e52c9ab2ba8"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/solana-web3/MAL-2026-11533.json"