-= Per source details. Do not edit below this line.=-
Package @solana-labs/web3.js impersonates the legitimate @solana/web3.js and re-exports it as cover while running a malicious postinstall (node install.js). On npm install, install.js performs sandbox-evasion checks (hostname pattern scoring for Docker/AWS/CI runners, /proc/uptime, presence of strace/tcpdump/auditd, AWS metadata 169.254.169.254, security-tooling dependencies) and aborts if it detects analysis. Otherwise it enumerates installer secrets — ~/.ssh/id_rsa, ~/.aws/credentials, ~/.config/solana/id.json, .env files, and scrapes process.env for KEY/SECRET/MNEMONIC/NPM/GITHUB tokens — and harvests crypto material including ETH private keys (/0x[a-fA-F0-9]{64}/), Solana 64-byte arrays, and AWS keys. Stolen data is tagged [ETH]/[SOLANA]/[AWS]/[SSH]/[NPM]/[GITHUB] and exfiltrated to api.telegram.org/bot<token>/... using XOR-obfuscated bot token, chat ID, and HMAC auth secret embedded in install.js. install.js then enters a long-poll loop against Telegram getUpdates accepting commands /keys, /ssh, /env, /wallet, /sh <cmd>, and bare text, executing them via execSync (PowerShell on Windows) and returning output to the attacker — a full reverse-shell C2 backdoor. Persistence is established via a @reboot sleep 90 && node <path> crontab entry. A hardcoded Solana drain address D4hGgKKaBFZV1NUTWvYRwbpu8HHr3qmDfHyKCTLqbaE7 is present for wallet theft.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-005289",
"import_time": "2026-06-10T19:23:48.407752036Z",
"modified_time": "2026-06-10T18:37:05Z",
"sha256": "91b0523027116b3981b0f1dfe925f01d8956eb19817aae6ea7d0022d5357fba4",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-005412",
"import_time": "2026-06-11T03:48:48.040739264Z",
"modified_time": "2026-06-11T02:56:32Z",
"sha256": "ecbc63549cc76fd907dd706b2179b18cd8c55b268dd09d8d9251bf809959d0ff",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-005413",
"import_time": "2026-06-11T03:48:48.167932571Z",
"modified_time": "2026-06-11T02:56:36Z",
"sha256": "4d8c1fbfa898eecbdb8a68ea66a8df992831e3e5162eaddefc00aac759bbeca6",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
},
{
"id": "IN-MAL-2026-005411",
"import_time": "2026-06-11T03:48:47.930436913Z",
"modified_time": "2026-06-11T02:56:32Z",
"sha256": "71cb6a46817602611ef7fff42f375bd177bcb9e0a896cf29dfdbd7e637ca8f11",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-005415",
"import_time": "2026-06-11T03:48:48.448091892Z",
"modified_time": "2026-06-11T02:56:43Z",
"sha256": "91b279bb9db78faa1c5e6093b86517d3203181c5b832cbc8a5389b10173eb9aa",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-005414",
"import_time": "2026-06-11T03:48:48.267985431Z",
"modified_time": "2026-06-11T02:56:40Z",
"sha256": "a72f1201ef049594dc4486cbb51dab1a840d8ff0ba9a9b54cabfd28bc16c0c60",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-005410",
"import_time": "2026-06-11T03:48:47.805030599Z",
"modified_time": "2026-06-11T02:56:19Z",
"sha256": "e2d5a23bad2592218c4af9410b15a1f7f5cf1700cf5a8241e3ffeec8106c53e6",
"source": "amazon-inspector",
"versions": [
"1.98.112"
]
},
{
"id": "RLMA-2026-05468",
"import_time": "2026-07-20T13:14:42.515632176Z",
"modified_time": "2026-07-20T10:28:16Z",
"sha256": "1ea5ec0b728f19e6e02f9cfccfe5a9fa8551e7111f295ee855432b0577a4f76b",
"source": "reversing-labs",
"versions": [
"1.0.0",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.10",
"1.98.102",
"1.98.104",
"1.98.107",
"1.98.108",
"1.98.109",
"1.98.110",
"1.98.111",
"1.98.112"
]
},
{
"id": "IN-MAL-2026-013037",
"import_time": "2026-08-05T06:00:33.813491678Z",
"modified_time": "2026-08-05T05:24:54Z",
"sha256": "2a67795794da6e4b097273b2be523977460f77d5413bc0d7df07330060f0f6f2",
"source": "amazon-inspector",
"versions": [
"1.98.111"
]
},
{
"id": "IN-MAL-2026-012990",
"import_time": "2026-08-05T06:00:28.090006071Z",
"modified_time": "2026-08-05T05:18:08Z",
"sha256": "32484704850faaf80d41e75ead1ca25f7ba6096ae16d6c8538fe24a01e169633",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-012976",
"import_time": "2026-08-05T06:00:26.564934928Z",
"modified_time": "2026-08-05T05:16:06Z",
"sha256": "7d6fe80182bdd6096ab1645a6bd2f9de0ac30bf39f685af3dfb49549d90fc3ff",
"source": "amazon-inspector",
"versions": [
"1.98.109"
]
},
{
"id": "IN-MAL-2026-013038",
"import_time": "2026-08-05T06:00:33.918579241Z",
"modified_time": "2026-08-05T05:25:04Z",
"sha256": "be0de94aefad1318068f493b4f74cc7a0a9ffb88274b3f4981953a911be113b5",
"source": "amazon-inspector",
"versions": [
"1.98.108"
]
},
{
"id": "IN-MAL-2026-012974",
"import_time": "2026-08-05T06:00:26.350044311Z",
"modified_time": "2026-08-05T05:15:48Z",
"sha256": "00e264030f557298d3f651819f219d0447fd8eb439e30c16b706298c9502c5a0",
"source": "amazon-inspector",
"versions": [
"1.98.110"
]
},
{
"id": "IN-MAL-2026-013040",
"import_time": "2026-08-05T06:00:34.172563115Z",
"modified_time": "2026-08-05T05:25:18Z",
"sha256": "8508140321a6b8b9f432191571d7448f5c4c800def7ea6a4ef022f86789fd670",
"source": "amazon-inspector",
"versions": [
"1.98.102"
]
},
{
"id": "IN-MAL-2026-012985",
"import_time": "2026-08-05T06:00:27.519644791Z",
"modified_time": "2026-08-05T05:17:23Z",
"sha256": "c5146752ab21ddadd078c087247c3b64ae24052e3206d061d6469c327b39b00b",
"source": "amazon-inspector",
"versions": [
"1.98.104"
]
},
{
"id": "IN-MAL-2026-012992",
"import_time": "2026-08-05T06:00:28.323047843Z",
"modified_time": "2026-08-05T05:18:27Z",
"sha256": "e7467de99130547c19764fe85036393b5e515fe889e16a0798ccc7a283ae002a",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-013041",
"import_time": "2026-08-05T06:00:34.396682672Z",
"modified_time": "2026-08-05T05:25:31Z",
"sha256": "f4071c22c2b443c1e5cec5e67ee9f593d10cd233b4896f57e71618f963cb3124",
"source": "amazon-inspector",
"versions": [
"1.98.107"
]
},
{
"id": "RLUA-2026-05925",
"import_time": "2026-09-01T11:17:44.575357788Z",
"modified_time": "2026-08-24T16:31:01Z",
"sha256": "8151aa214db21c8e50450e5b3d9087dd7c091ec1fcea7aa2a07e69c2511bca4f",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"ifconfig.me",
"api.telegram.org"
],
"evidence_files": [
{
"path": "install.js",
"sha256": "e2f55065f26c6337b01f1e944df3f4c13a374b1b47ee8771a5e5680f9324c97e",
"tlsh": "3c4219bbf7a993b8c69a20785e1fb10b947b79134d84e144f85ce4826f6c24413a7cf9"
}
],
"package_integrity": [
{
"filename": "web3.js-1.0.7.tgz",
"hashes": {
"sha1": "6521dabf12b7042da38d9f566ed10f74ad32b77a",
"sha512_sri": "sha512-tlYdcAHCeVemdvK8j8FpPJU4oBgQxguv3BMp4EDOXq16nd9D7YEVy7li4ilkGYXdw+wf7gJS3POOtDokbseIwQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@solana-labs/web3.js/MAL-2026-5525.json"