{"id":"MAL-2026-11534","summary":"Malicious code in @zzzgenesis00/xrp-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (49ad59aa1c004d723d6e24f8113d8f3d45728c0b26fc41531ec00c0f91d2ddef)\nThe package impersonates XRPLF's xrp-lib (author metadata and homepage point at github.com/XRPLF/xrp-lib) while being published under an unrelated scope. Its postinstall.js runs automatically on npm install and collects host metadata, iterates ~40 credential-shaped environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, MNEMONIC, SEED_PHRASE, ETHEREUM_PRIVATE_KEY, and similar), reads ~/.ssh, ~/.npmrc, and ~/.gitconfig, indexes Chrome/Firefox profile stores, runs `npm whoami` and `git config`, and enumerates wallet directories. The harvested profile is exfiltrated via two hardcoded non-first-party destinations: api.telegram.org using a hardcoded bot token and chat id, and https://40f955f39128bd79-178-249-214-24.serveousercontent.com/collect via POST. Identifiers are mangled (_uzy/_cod/_ndz/_cp/_ht/_tk/_ch), the payload is disguised with a 'postinstall environment verification' comment, and exfil is delayed via setTimeout with a 1.5–3.5s random jitter to hide from install traces.\n","modified":"2026-08-04T23:04:48.687802950Z","published":"2026-08-04T22:07:35Z","database_specific":{"malicious-packages-origins":[{"versions":["2.14.0"],"id":"IN-MAL-2026-011341","import_time":"2026-08-04T22:30:11.768657804Z","modified_time":"2026-08-04T22:07:35Z","sha256":"49ad59aa1c004d723d6e24f8113d8f3d45728c0b26fc41531ec00c0f91d2ddef","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/xrp-lib/v/2.14.0"}],"affected":[{"package":{"name":"@zzzgenesis00/xrp-lib","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/xrp-lib"},"versions":["2.14.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"263baeab3406bce9899e462ba25c6ce0f74bf926df42d49ea629971c3bbb78c2","tlsh":"5ad1729622e6031c6892a9ad878f10241676e0433818fbf8bedd5f510f4e52cdaf57ac","path":"postinstall.js"}],"package_integrity":[{"hashes":{"sha1":"8ec99e004cffc482d1c76ac614d4ff9b10246edd","sha512_sri":"sha512-WpF15k2SCyqE9Rg949fUDCOq5uo/Pvt83dOiQC8K66fu71QkAUcMoaAKAgM9VGYeKatP1M0EK0i1WRz8lgF7JA=="},"filename":"xrp-lib-2.14.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/xrp-lib/MAL-2026-11534.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}