-= Per source details. Do not edit below this line.=-
postinstall.js runs automatically on npm install and enumerates installer-side secret stores including ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome and Firefox profile paths, and cryptocurrency wallet directories, and collects a hardcoded list of secret environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS keys, MNEMONIC, SEED_PHRASE, ETHEREUM_PRIVATE_KEY, and other API keys). The harvested profile is transmitted at install time via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and via HTTPS POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com (a serveo reverse-tunnel host), with a randomized 1.5-3.5s delay. package.json declares author apocas and repository github.com/apocas/docker-api-client, impersonating the maintainer of the legitimate dockerode/docker-modem packages; the scoped name @zzzgenesis00/docker-api-client is unrelated to that author.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-011963",
"import_time": "2026-08-05T03:12:04.484716586Z",
"modified_time": "2026-08-05T02:52:08Z",
"sha256": "2417f0620e130c16865914c5f79fdff63bdda0daf3257955c8fd536ab894c1b1",
"source": "amazon-inspector",
"versions": [
"2.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "8598c30926f1aab97f9ab633cfea6989523295ae6012b500f68f55f299471135",
"tlsh": "74d1439a12f603186c92a9ae8f8f40241676d1173920fbf83fcd07514f4e53db6b57a8"
},
{
"path": "package.json",
"sha256": "d74b7a7de01ba4b65f137a2a1df9389f94a9d67dbf929232c4526da3025695aa",
"tlsh": "a3012614c9612a732ad45b889c564182a7368c578a04bc0923ab42ac9b9f07b11fe14d"
}
],
"package_integrity": [
{
"filename": "docker-api-client-2.0.2.tgz",
"hashes": {
"sha1": "68716daa88cd941dcb2ed905f24d4fc9e4fc6741",
"sha512_sri": "sha512-inDNdzsch1+U2q9r8idx9UuTtE+5/wu55dQ76SSUeyYCqbQU0nQ/xovqU2qX1ZdvgA4zdZKSoxmUHBXJsdGHNQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/docker-api-client/MAL-2026-12055.json"