-= Per source details. Do not edit below this line.=-
Package impersonates the bitcoinjs/bip39 project (author field set to 'bitcoinjs-lib') and ships a postinstall.js that runs on npm install. The script collects host/user identifiers and a curated list of sensitive environment variables (including NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_* keys, and wallet-related PRIVATE_KEY/MNEMONIC/SEED_PHRASE), enumerates ~/.ssh, reads ~/.npmrc and ~/.gitconfig, probes Chrome/Firefox profile artifacts and crypto wallet directories, and shells out to npm whoami and git config. The collected JSON is transmitted to two hardcoded destinations: the Telegram Bot API (bot token and chat_id 7231970337 embedded in the script) and a POST to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Exfiltration is delayed by a randomized setTimeout (1500 + rand*2000 ms) and the module re-exports./index.js to appear legitimate.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-011471",
"import_time": "2026-08-05T01:39:30.493022006Z",
"modified_time": "2026-08-05T00:53:35Z",
"sha256": "7f370f7bfdab3817c323daee33d8de48e5171c41dad3f1bff2f1335e04a65060",
"source": "amazon-inspector",
"versions": [
"2.3.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "8ff3ace595efd90d97570c02bfc3273fc408387719b07061d7b7c044ee149356",
"tlsh": "4fd161a612ea031c5952a9ad4b4f00251673e1033c20faf67ecc0f620f5e52cdab97ac"
}
],
"package_integrity": [
{
"filename": "bip39-mnemonic-2.3.1.tgz",
"hashes": {
"sha1": "ab91f9c4e573437f4bce8515ef6c13b7fdcbd16d",
"sha512_sri": "sha512-eqW6jBkvQovUwf+XnMW2swGiJGbfabXvJM+CLlAQrF7J3eh+BlDoy0nYb7F99wyPb2mG1f3oJokvWkkSuqi6nA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/bip39-mnemonic/MAL-2026-12030.json"