{"id":"MAL-2026-11533","summary":"Malicious code in @zzzgenesis00/solana-web3 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (433d4c4c3c8984e1fdd1a47623a9d5cf7c464ff9a64ce32846a76f10e3224dce)\nThis package impersonates Solana Labs (author field 'solana-labs', repository pointing at github.com/solana-labs/solana-web3) under an unrelated scope. Its postinstall.js runs automatically on npm install and, after a 1.5-3.5 second randomized delay, harvests installer-owned secrets: files under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile artifacts (Cookies, Login Data, key4.db), and cryptocurrency wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus, and Electrum/Exodus AppData). It also iterates a hardcoded list of credential-shaped environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKEN, DOCKER_PASSWORD, GCLOUD_ACCESS_TOKEN, MNEMONIC, SEED_PHRASE, multiple *_PRIVATE_KEY variables, and HELIUS/INFURA/ALCHEMY API keys). The collected profile is transmitted to two attacker-controlled destinations: the Telegram Bot API (bot 7231970337, chat_id 7231970337) via GET, and a serveo.net dynamic tunnel host at 40f955f39128bd79-178-249-214-24.serveousercontent.com via POST /collect. Variable identifiers in the script are masked (_jku, _wjn, _hyz, _ht, _tk, _ch) and the exfiltration is deferred behind a randomized timer to evade observation during install.\n","modified":"2026-08-04T23:04:49.372367629Z","published":"2026-08-04T22:08:48Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["2.1.0"],"id":"IN-MAL-2026-011350","import_time":"2026-08-04T22:30:12.124393921Z","modified_time":"2026-08-04T22:08:48Z","sha256":"433d4c4c3c8984e1fdd1a47623a9d5cf7c464ff9a64ce32846a76f10e3224dce"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/solana-web3/v/2.1.0"}],"affected":[{"package":{"name":"@zzzgenesis00/solana-web3","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/solana-web3"},"versions":["2.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"44d174a712d503995457aead478f00241632e1073d30faf47fce5b564f4e52c9ab2ba8","path":"postinstall.js","sha256":"cc719f4ba4f0a427f12e90a88f3b7cd83395f258ddaf220ce4e8e6c86dadcfde"}],"package_integrity":[{"hashes":{"sha1":"226b7d7b2e62f5ce24f7754996d36fd7d2ebf413","sha512_sri":"sha512-Kp8CRGvuEUsqiL/kAdpcIa3rmq357r0armBh5Z9HIaYRS8dMWUg3fDpO2PNl8aYcHQNGdu3z5E/oB8DluGIumA=="},"filename":"solana-web3-2.1.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/solana-web3/MAL-2026-11533.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}