{"id":"MAL-2026-11994","summary":"Malicious code in @zzzgenesis00/web3-provider-engine (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fae571005ccdcdc23e50fbee1eddc31d39355706b7945df3ccbb3096ecaf724b)\nPackage impersonates MetaMask's web3-provider-engine (author field 'MetaMask', homepage pointing to github.com/MetaMask/web3-provider-engine) while shipping a postinstall.js that runs automatically on npm install and harvests installer secrets. postinstall.js reads ~/.ssh contents, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile databases (Cookies, Login Data, key4.db), enumerates crypto wallet directories (.bitcoin,.ethereum,.metamask,.exodus, and others), invokes npm whoami and git config, and captures roughly 30 credential-shaped environment variables including NPM_TOKEN, GITHUB_TOKEN, AWS keys, PRIVATE_KEY, MNEMONIC, SEED_PHRASE, and multiple chain-specific *_PRIVATE_KEY values. The collected data is JSON-serialized and transmitted to two hardcoded non-first-party destinations: api.telegram.org/bot\u003ctoken\u003e/sendMessage via GET with a hardcoded bot token and chat_id, and https://40f955f39128bd79-178-249-214-24.serveousercontent.com/collect via POST. index.js provides a stub web3 API surface (createWallet, generateMnemonic returning random bytes) to appear functional and disguise the harvest.\n","modified":"2026-08-05T00:37:45.573314922Z","published":"2026-08-04T23:52:49Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["16.0.5"],"id":"IN-MAL-2026-011353","import_time":"2026-08-05T00:04:38.126621737Z","modified_time":"2026-08-04T23:52:49Z","sha256":"fae571005ccdcdc23e50fbee1eddc31d39355706b7945df3ccbb3096ecaf724b"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/web3-provider-engine/v/16.0.5"}],"affected":[{"package":{"name":"@zzzgenesis00/web3-provider-engine","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/web3-provider-engine"},"versions":["16.0.5"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"ce164f82a89b85c8a131a2a3ee3f2d3a2bb5654233d62db7c74b6d935c5a714e","tlsh":"18d195a612e603195852b9ad87af00152633e1437838fbf87ecc5b514f4d52cdab2bb8"},{"path":"package.json","sha256":"6cc09802e9b683c55dae3c245c54271a6a3a40003d33694110376edb9bb66bb2","tlsh":"d2017635c4106e731ac81e84bc9a0ac3bb394e070804b81863c7016ceb4fa6725fd99d"}],"package_integrity":[{"filename":"web3-provider-engine-16.0.5.tgz","hashes":{"sha1":"9e32129f0e21c3320694720ce8cbbd044af6ba9c","sha512_sri":"sha512-gX5ubmn2CEaLAmz4Uuo4okc09jOfo3WgZhPxpwXyJUa0Ya8tV2KQxu+WarDKbWfpaozimP2E/llEh2tIZYvsVg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/web3-provider-engine/MAL-2026-11994.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}