-= Per source details. Do not edit below this line.=-
@zzzcrypto/solana-spl-token@0.4.0 is a typosquat/impersonation of @solana/spl-token (README self-describes as a 'drop-in replacement'; author metadata is set to 'solana-labs'). On module load, index.js enumerates the full process.env and augments it with hostname, username, homedir, platform, and cwd, base64-encodes the JSON payload, and sends it as an HTTPS GET to api.telegram.org/bot/sendMessage with chat_id=8969499041. A temporary flag file gates the beacon to once per host. Variable names are randomized (dmcp, uqxj, bhhs, _h, flag) and the payload is base64-wrapped to hide the exfil body. If the real @solana/spl-token is not installed, the package falls back to a stub API exporting createWallet/generateMnemonic that returns random bytes rather than real key material. On typical developer and CI machines, process.env contains credentials such as AWS*, GITHUB_TOKEN, and NPM_TOKEN, which are shipped off-host to the attacker's Telegram chat.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-015739",
"import_time": "2026-08-05T16:13:38.714577941Z",
"modified_time": "2026-08-05T15:32:40Z",
"sha256": "6ceac45508e2f9506a082b2195d3bae4b046f096d11856d72ea53f784ad5992e",
"source": "amazon-inspector",
"versions": [
"0.4.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "963f4cb0eb93714a1f3571f6c031f997cb569a155f08d8dfcbaf349bf64746b2",
"tlsh": "842179cc27f2bd8d16377592982f600bb27bc5b60488f614c564e1c37f705c85a16b94"
}
],
"package_integrity": [
{
"filename": "solana-spl-token-0.4.0.tgz",
"hashes": {
"sha1": "5a58f9527691d4fe79312f255b37030bd8f239a7",
"sha512_sri": "sha512-cgNJ2tr33WJzziEOqQtvEyY+kjY4Veoy102YcCrbmb96zvBOXo0X21h96t8cQ3WeAbM86f9YX3zKbF0usv9tEA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzcrypto/solana-spl-token/MAL-2026-13214.json"