{"id":"MAL-2026-11531","summary":"Malicious code in @zzzgenesis00/hdkey-wallet (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cc9f452c698c4accd69ca2df75854aae3189ecf3dddafc4b62d86403ca3d911f)\nOn npm install, scripts.postinstall executes postinstall.js which harvests installer-side secrets and host reconnaissance and transmits them to attacker-controlled destinations. Collected data includes: hostname, username, homedir, platform, arch, Node version, and cwd; contents/metadata of ~/.ssh, ~/.npmrc, and ~/.gitconfig; browser credential store paths (Chrome/Firefox cookies, login data, key4.db); presence of wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum,.tron, etc.); and roughly 30 credential-shaped environment variables including NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, PRIVATE_KEY, MNEMONIC, and SEED_PHRASE. The aggregated payload is sent to api.telegram.org via a hardcoded bot token and chat id, with a secondary POST channel to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. The package is published under the unrelated @zzzgenesis00 scope while its metadata impersonates the cryptocoinjs maintainer and points its homepage at github.com/cryptocoinjs/hdkey-wallet; identifiers in the postinstall are obfuscated (_wgw, _ddo, _bkv, _cp, _ht, _tk, _ch) and framed with a cover comment describing 'postinstall environment verification'.\n","modified":"2026-08-04T23:04:47.294900759Z","published":"2026-08-04T22:07:43Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-011342","import_time":"2026-08-04T22:30:11.803138833Z","modified_time":"2026-08-04T22:07:43Z","sha256":"cc9f452c698c4accd69ca2df75854aae3189ecf3dddafc4b62d86403ca3d911f","source":"amazon-inspector","versions":["2.1.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/hdkey-wallet/v/2.1.0"}],"affected":[{"package":{"name":"@zzzgenesis00/hdkey-wallet","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/hdkey-wallet"},"versions":["2.1.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"87cf7699a1ef72eb0b30830a4c22757a8731915e","sha512_sri":"sha512-a2SN9UJ970fudaBJIGYY5HA6sTbxo4sAdMo2q23bxzL68V/jOev1A5oLbDLjtKBs3O/kKwA+COnEsdTwn6q3uw=="},"filename":"hdkey-wallet-2.1.0.tgz"}],"evidence_files":[{"sha256":"a74f93e842f5a95283f70ff27f6b084fa29365ac6ffdbe70c85a5117211a5ec1","tlsh":"0fd182d212e6131c5892a9ad479f90211632e4033820fbf93fdd07a24f4e42c9bf17a8","path":"postinstall.js"},{"path":"package.json","sha256":"5f12e636670c467da53c2a84c6e389e47dc70f54b79410f191ca3389c92ce239","tlsh":"47017b10ca50fe3316d92a858c7545a7b2654c578904bc6933e7409c5b9e47b0afe12d"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/hdkey-wallet/MAL-2026-11531.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}