-= Per source details. Do not edit below this line.=-
@zzzgenesis00/hd-key-generator ships a postinstall.js that runs automatically on npm install. It enumerates ~/.ssh, ~/.npmrc, ~/.gitconfig, browser profile artifacts (Chrome/Firefox cookies, Login Data, key4.db), and cryptocurrency wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum), and scrapes environment variables shaped as credentials (NPMTOKEN, NODEAUTHTOKEN, GITHUBTOKEN, AWS_*, *PRIVATEKEY, MNEMONIC, SEEDPHRASE, API keys). The collected data is transmitted via two hardcoded channels: an HTTPS GET to api.telegram.org bot sendMessage using an embedded bot token and chatid, and an HTTPS POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com. The payload is self-labeled as 'postinstall environment verification', uses cryptic identifiers (_cgn, _qik, _gso, _cp, _ht, _tk, _ch, _co, _ex), and is triggered via setTimeout with random jitter to obscure execution. index.js is a thin wrapper that re-exports the legitimate 'hdkey' module when present, providing a typosquat-style cover for HD-wallet developers while the stealer runs.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-05T09:28:05.166181612Z",
"sha256": "6d1bce1ae0778169c4e5fb37721dfcc052c984efc60a257166adb4d20e2d39e5",
"modified_time": "2026-08-05T08:42:59Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-014387",
"versions": [
"1.6.3"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/hd-key-generator/MAL-2026-12121.json"
{
"evidence_files": [
{
"sha256": "ff6ffdeaf72d49c2898a142ff9ffd50ef7fd62730bbcb4ab641e6ff08a9b4ccb",
"path": "postinstall.js",
"tlsh": "80d164e323ea23186896b9ae474f40145632d2533810faf43fde1716af4d93c97b57a8"
},
{
"sha256": "82d7b06c99e710f301f4a6dcf646fab500324f88297278917b36fb0e4f81efce",
"tlsh": "8d119c922bf2f2140bc5f0a5d563c04be5b8e99305ac6229f64d792777f8548c0b1dd4",
"path": "index.js"
}
],
"package_integrity": [
{
"filename": "hd-key-generator-1.6.3.tgz",
"hashes": {
"sha1": "5c0c662c00ff80d8568a7311b4952682e3d7e895",
"sha512_sri": "sha512-pBjowAY3mqQxzfags3RwOCluA1wkZTZBxA2NJfErBpez9GHNWQQ9URVRCY3uWUWKWlbd3PGD4AV8bth4PKa07g=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]