@openzeppelin-4/contracts is a malicious npm package published by npm account mssjeep843 that impersonates OpenZeppelin's @openzeppelin/contracts (the v4 line) via the look-alike scope @openzeppelin-4, falsely describing itself as a "compatibility distribution". It ships no Solidity contracts — only an install-time payload (index.js) run via preinstall/postinstall that harvests credential-shaped environment variables and reads and exfiltrates SSH private keys, cloud credentials (AWS/GCP/Kubernetes/Docker), Solana/Anchor/NEAR/Sui wallet keys, Foundry keystores, .git-credentials and local .env files to https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09. It is one of a series of DeFi/crypto impersonation packages from the same account sharing this webhook.site endpoint, which also squat Aerodrome Finance, Camelot AMM, Euler EVC, BoringVault and Uniswap Permit2.
-= Per source details. Do not edit below this line.=-
Package name @openzeppelin-4/contracts impersonates the @openzeppelin/contracts scope but ships no Solidity contracts — only index.js, executed via lifecycle scripts. index.js enumerates process.env for credential-shaped keys (KEY, TOKEN, SECRET, AWS, GITHUB, NPM, MNEMONIC, WALLET, INFURA, etc.), reads installer secret files including ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.kube/config, ~/.docker/config.json, ~/.netrc, ~/.npmrc, ~/.gitconfig, ~/.git-credentials, gcloud application default credentials, Solana/Anchor/Sui keys, Foundry keystores, and project.env files, then POSTs the collected data to https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09. Delivery uses spawn(process.execPath, ['-e', src], { detached: true, stdio: 'ignore' }) with a randomized 60–240 second delay, and the script bails out when the hostname or username matches sandbox/scanner patterns (scan-, detonation, sandbox, ubuntu-fc-uvm) or when canary env markers are present, evading install-time analysis.
{
"iocs": {
"urls": [
"https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09"
]
},
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017361",
"import_time": "2026-08-11T15:26:48.469062997Z",
"modified_time": "2026-08-11T15:16:48Z",
"sha256": "2841eb854dad391b8cf3d290704a888d5ac186a1f51aec84594eaa09acdfeb68",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-017364",
"import_time": "2026-08-11T15:26:48.833021928Z",
"modified_time": "2026-08-11T15:17:15Z",
"sha256": "af69458eaa45c49ecd88e7c778bb02f44871683f400ae81b9e5640e8c1710842",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "b7d297845b21b9e50cb6b4229f60adbd7af572f1c8038b56db8213be1436fd13",
"tlsh": "9451b683a2fe55a9126393e5e6236235823bf240b016d4e4f3ac54415fdb164c9b35fc"
},
{
"path": "package.json",
"sha256": "40792c0d6846ac1e32a7cc51bf22be727b2cc4b5c9afc16221226b26c4da2468",
"tlsh": "e8e026300d52a33321e00ad6257bc85da0a6aa1a51883c0553c361ce82edb7284ff60e"
}
],
"package_integrity": [
{
"filename": "contracts-1.0.1.tgz",
"hashes": {
"sha1": "0d49caf08b7ed3f15b70426b187a7647c403e4d8",
"sha512_sri": "sha512-xdFmvYYbmuGfHKfOq/nSSHuYT5vjUv5pNFESA2qvIam+k0e1zJbnw1+NR35TZvcA6vMlhK4MLhK464uj09Cf8A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@openzeppelin-4/contracts/MAL-2026-13737.json"