{"id":"MAL-2026-11995","summary":"Malicious code in approval-guardian (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (71875c984aab2d8335b3efdd1b107d7adbd4c3cbd6309278b6804c8162bdca87)\nThe package presents itself as an on-chain approval scanner but on CLI invocation runs a silent credential harvester. src/index.js scan() walks the installer's AppData/Roaming, AppData/Local, ~/.config, and ~/.local/share directories matching wallet-application keywords (Exodus, Electrum, Atomic, MetaMask, Trust, Coinbase, Binance, OKX, Phantom, Rabby, Ledger, BraveWallet), reads the matched files, and extracts EVM addresses. src/collector.js contains a hardcoded map of Chromium wallet extension IDs (MetaMask nkbihfbeogaeaoehlefnkodbefgpgknn, Phantom, Trust, Exodus, etc.) used to read browser Local Extension Settings, plus paths to browser Login Data / Local State and to 1Password, LastPass, Bitwarden, KeePass, and Dashlane vault stores. collector.js also embeds a Windows keylogger implemented via an inline PowerShell/C# block using System.Windows.Forms and System.Runtime.InteropServices DllImport low-level hooks, self-described in a header comment as 'Windows keylogger (MetaMask unlock / form passwords)'. Collected data is POSTed to the hardcoded endpoint https://chainpulse-api-vf5g.onrender.com defined as C2_URL at src/collector.js line 16. An author comment in src/index.js states 'The stealer operates silently in a parallel thread — zero user impact', confirming the covert design behind the advertised scanner functionality.\n","modified":"2026-08-05T13:34:58.082105761Z","published":"2026-08-04T23:58:44Z","database_specific":{"malicious-packages-origins":[{"sha256":"59385ed84d208c075fbee8edac062893c67a872160200f581dc769e0a0b58c2f","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-011363","import_time":"2026-08-05T00:04:39.071490233Z","modified_time":"2026-08-04T23:59:14Z"},{"modified_time":"2026-08-04T23:58:44Z","sha256":"71875c984aab2d8335b3efdd1b107d7adbd4c3cbd6309278b6804c8162bdca87","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-011362","import_time":"2026-08-05T00:04:38.978759468Z"},{"id":"IN-MAL-2026-014614","import_time":"2026-08-05T09:28:30.686687489Z","modified_time":"2026-08-05T09:15:59Z","sha256":"43da8ae79417e0cf71c99271cbf92a33a4265de8f789f06f3ca3b99cc1126d3d","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-014652","import_time":"2026-08-05T13:08:34.068807841Z","modified_time":"2026-08-05T12:25:47Z","sha256":"8fd801f55c322330459648aee7a2c51d5a16e2748bbfb39f5dfe0323556ec223","source":"amazon-inspector","versions":["1.0.2"]},{"modified_time":"2026-08-05T12:25:40Z","sha256":"e7f93d324e48d21f6f30649ac9804b418d9a10c40679f065382bad5eefe0dc12","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-014651","import_time":"2026-08-05T13:08:33.960249332Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/approval-guardian/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/approval-guardian/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/approval-guardian/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/approval-guardian/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/approval-guardian/v/1.0.3"}],"affected":[{"package":{"name":"approval-guardian","ecosystem":"npm","purl":"pkg:npm/approval-guardian"},"versions":["1.0.1","1.0.6","1.0.5","1.0.2","1.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/approval-guardian/MAL-2026-11995.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"src/collector.js","sha256":"77a356320fce0d442276a4b881cbf92ad36eec9cf7a55d8562f034bc9c02d2fc","tlsh":"44a1a5c122fa233495a3f5dae20f94226166e012744adee0bf8c13441f4757ca3b6edd"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-tIkBrtACqil2vXQzrdJWUj1W9DsUW6UGOWkkUkm+2cMfWQru7WV1BmkuFPmaMFVWHi4KalfAVWcaZpBG+HrNjw==","sha1":"8c527b8aea4a66e41aa64e786b6f2001c0d41b1d"},"filename":"approval-guardian-1.0.1.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}