MAL-2026-17516

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/oleh-modal/MAL-2026-17516.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17516
Published
2026-10-04T23:27:14Z
Modified
2026-10-04T23:45:20Z
Summary
Malicious code in oleh-modal (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545)

Package oleh-modal@1.0.0 is a credential-harvesting phishing kit disguised as a wallet-connect modal component. It renders fake MetaMask/Phantom/Rabby/OKX 'restore vault' modals that link to the legitimate extensions' restore-vault URLs to reinforce the deception, then captures the user's typed seed phrase / password characters via sendKeyToBackendAPI and POSTs them to a hardcoded backend at https://api.wagmiwallet.org/api/keys along with wallet_type, user_id, and enriched geolocation metadata (IP via api.ipify.org, city/region/country via ipapi.co). A persistent WebSocket connection to wss://api.wagmiwallet.org subscribes to a 'showMacModal' event that lets a remote operator trigger a spoofed macOS admin-authentication prompt on demand in the host application; captured mac_user_name and keystrokes from that dialog are forwarded through the same exfiltration path. Configuration references serverUrl 'https://wagmirequest.la' and backendUrl 'https://api.wagmiwallet.org', typosquats of wagmi.sh. Any consumer application that renders this component will forward its end users' wallet mnemonics and OS credentials to the attacker endpoint.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020965",
            "import_time":  "2026-10-04T23:40:46.543978657Z",
            "modified_time":  "2026-10-04T23:27:14Z",
            "sha256":  "cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / oleh-modal

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "dist/index.cjs",
            "sha256":  "e8bc1ad8e8628a784a23f739004c3a6d53160311e2311933ab751d5dc7f5f7e9",
            "tlsh":  "bec4fad4b3ad106e4123716aa93f11cdb33dd173561488a9be9c992c3fd481c43eabb9"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "oleh-modal-1.0.0.tgz",
            "hashes":  {
                "sha1":  "66e05aa225714eac39ea6bd3205000dc22729433",
                "sha512_sri":  "sha512-EUXUoDIY5L/ONz5Jcc07jt/41HEYV3YALtX/pNzmqzbo6vkxKJ/lxXVYPcuIAM7vXMpOa0Id3X5nCTlSJt4pQg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/oleh-modal/MAL-2026-17516.json"