-= Per source details. Do not edit below this line.=-
Package oleh-modal@1.0.0 is a credential-harvesting phishing kit disguised as a wallet-connect modal component. It renders fake MetaMask/Phantom/Rabby/OKX 'restore vault' modals that link to the legitimate extensions' restore-vault URLs to reinforce the deception, then captures the user's typed seed phrase / password characters via sendKeyToBackendAPI and POSTs them to a hardcoded backend at https://api.wagmiwallet.org/api/keys along with wallet_type, user_id, and enriched geolocation metadata (IP via api.ipify.org, city/region/country via ipapi.co). A persistent WebSocket connection to wss://api.wagmiwallet.org subscribes to a 'showMacModal' event that lets a remote operator trigger a spoofed macOS admin-authentication prompt on demand in the host application; captured mac_user_name and keystrokes from that dialog are forwarded through the same exfiltration path. Configuration references serverUrl 'https://wagmirequest.la' and backendUrl 'https://api.wagmiwallet.org', typosquats of wagmi.sh. Any consumer application that renders this component will forward its end users' wallet mnemonics and OS credentials to the attacker endpoint.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020965",
"import_time": "2026-10-04T23:40:46.543978657Z",
"modified_time": "2026-10-04T23:27:14Z",
"sha256": "cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.cjs",
"sha256": "e8bc1ad8e8628a784a23f739004c3a6d53160311e2311933ab751d5dc7f5f7e9",
"tlsh": "bec4fad4b3ad106e4123716aa93f11cdb33dd173561488a9be9c992c3fd481c43eabb9"
}
],
"package_integrity": [
{
"filename": "oleh-modal-1.0.0.tgz",
"hashes": {
"sha1": "66e05aa225714eac39ea6bd3205000dc22729433",
"sha512_sri": "sha512-EUXUoDIY5L/ONz5Jcc07jt/41HEYV3YALtX/pNzmqzbo6vkxKJ/lxXVYPcuIAM7vXMpOa0Id3X5nCTlSJt4pQg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/oleh-modal/MAL-2026-17516.json"