-= Per source details. Do not edit below this line.=-
On require(), index.js collects the full process.env object together with hostname, username, home directory, platform, current working directory, and a timestamp, JSON-encodes and base64-encodes the payload, and issues an HTTPS GET to api.telegram.org/bot/sendMessage with a hardcoded bot token and chat_id. A tmp-file flag suppresses re-sending. The package advertises itself as a 'Drop-in replacement for bitcoinjs-lib' under an unrelated scope and ships only stub wallet functions alongside this exfiltration payload, consistent with a typosquat lure targeting bitcoinjs-lib users. In modern development and CI environments, process.env routinely contains cloud credentials, npm/GitHub tokens, and database passwords, all of which are sent to the attacker-controlled Telegram chat on module load.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-013448",
"import_time": "2026-08-05T07:06:47.939782616Z",
"modified_time": "2026-08-05T06:24:40Z",
"sha256": "94f602036ff9f524298056528fbec6c58c9fb66ea2686bec418694b5854aeea4",
"source": "amazon-inspector",
"versions": [
"5.4.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "3d3afcdc0d19893d0b3b9448f5f98f669bb799388a036204fd12d688d871297c",
"tlsh": "182166dc27f1f94e22336142542f610ab2bbdae20488e661d5a4d0c76f741cc8d6578c"
}
],
"package_integrity": [
{
"filename": "bitcoinjs-wallet-5.4.2.tgz",
"hashes": {
"sha1": "3e4d74e82b4957f614894357e53b73713f10b5f1",
"sha512_sri": "sha512-NaTj2ORja1/HDr9AvfSfgE4je3AYkD5VqMKiVJ4M9BRfpQMEaXTPoOAOYmhTtBHAD5/m5zdO2BJjGU+9FYJHog=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/bitcoinjs-wallet/MAL-2026-12088.json"