-= Per source details. Do not edit below this line.=-
Package impersonates the bitcoinjs/bip39 project (author field set to 'bitcoinjs-lib') and ships a postinstall.js that runs on npm install. The script collects host/user identifiers and a curated list of sensitive environment variables (including NPMTOKEN, NODEAUTHTOKEN, GITHUBTOKEN, AWS_* keys, and wallet-related PRIVATEKEY/MNEMONIC/SEEDPHRASE), enumerates ~/.ssh, reads ~/.npmrc and ~/.gitconfig, probes Chrome/Firefox profile artifacts and crypto wallet directories, and shells out to npm whoami and git config. The collected JSON is transmitted to two hardcoded destinations: the Telegram Bot API (bot token and chat_id 7231970337 embedded in the script) and a POST to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Exfiltration is delayed by a randomized setTimeout (1500 + rand*2000 ms) and the module re-exports./index.js to appear legitimate.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-05T00:53:35Z",
"sha256": "7f370f7bfdab3817c323daee33d8de48e5171c41dad3f1bff2f1335e04a65060",
"id": "IN-MAL-2026-011471",
"versions": [
"2.3.1"
],
"import_time": "2026-08-05T01:39:30.493022006Z"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-eqW6jBkvQovUwf+XnMW2swGiJGbfabXvJM+CLlAQrF7J3eh+BlDoy0nYb7F99wyPb2mG1f3oJokvWkkSuqi6nA==",
"sha1": "ab91f9c4e573437f4bce8515ef6c13b7fdcbd16d"
},
"filename": "bip39-mnemonic-2.3.1.tgz"
}
],
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "8ff3ace595efd90d97570c02bfc3273fc408387719b07061d7b7c044ee149356",
"tlsh": "4fd161a612ea031c5952a9ad4b4f00251673e1033c20faf67ecc0f620f5e52cdab97ac"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/bip39-mnemonic/MAL-2026-12030.json"