MAL-2026-15984

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gas-price-checker/MAL-2026-15984.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-15984
Aliases
  • GHSA-fw8f-xwq4-q3v8
Published
2026-09-05T19:26:13Z
Modified
2026-09-08T19:30:04Z
Summary
Malicious code in gas-price-checker (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7f8f9689168acafb514d0ab0bb8710f1fce42e95560a2a0c7e0e6788e913e729)

Package advertises itself as a public-RPC gas price checker but on first call to the exported getGasPrice() API in src/envcheck.cjs it walks the caller's project directory scanning.env/.json/.js/.ts/keystore files with regexes for EVM private keys (0x[64 hex]), BIP-39 mnemonics, and strings matching private_key/mnemonic/api_key/secret/seed patterns. Matches (up to 40) are combined with a host fingerprint (sha256 of hostname|username), node version, and platform, encrypted with AES-256-GCM using a hardcoded base64 key (KEY_B64='Kkb8JVtVelmQmot/kC3JyY3WbjKH+LPln11DJ+bbTM0='), and POSTed to https://pkg-delivery-collector.vernal-dabs-tools.workers.dev/ingest. The scan and upload are gated by a one-shot _checked flag and run unconditionally the first time the advertised API is invoked. The exfiltration destination is undocumented, unrelated to the package's stated purpose (which requires no credentials), and the payload is encrypted with a shipped key to evade network inspection.

Source: ghsa-malware (459859928579f02596c8be07aa74f3388231d9fc9e94682740bde811d2ac3439)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "GHSA-fw8f-xwq4-q3v8",
            "import_time":  "2026-09-07T01:51:49.852995Z",
            "modified_time":  "2026-09-05T19:26:13Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "SEMVER"
                }
            ],
            "sha256":  "459859928579f02596c8be07aa74f3388231d9fc9e94682740bde811d2ac3439",
            "source":  "ghsa-malware"
        },
        {
            "id":  "IN-MAL-2026-019690",
            "import_time":  "2026-09-08T19:15:04.423676379Z",
            "modified_time":  "2026-09-08T19:09:50Z",
            "sha256":  "7f8f9689168acafb514d0ab0bb8710f1fce42e95560a2a0c7e0e6788e913e729",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / gas-price-checker

Package

Name
gas-price-checker
View open source insights on deps.dev
Purl
pkg:npm/gas-price-checker

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "src/envcheck.cjs",
            "sha256":  "d3f2dbe189c1138811ac2a2b4c5f4cd1e9334776fea314be95d277e98e0a6696",
            "tlsh":  "cd7196e835fba13547d710f572539096b3ba80533a42e9e4bb6c42142f8583c82b7ec9"
        },
        {
            "path":  "src/index.js",
            "sha256":  "a03093b85f3f985fa7e6c0cfc29dfda3b212afb1d770267d4e575efed8cb3b4c",
            "tlsh":  "cf2152f705b715a0836a36c2754f000ab32741867b4dacd5b7ee46109f5a6bac2526dc"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gas-price-checker/MAL-2026-15984.json"