{"id":"MAL-2026-12030","summary":"Malicious code in @zzzgenesis00/bip39-mnemonic (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7f370f7bfdab3817c323daee33d8de48e5171c41dad3f1bff2f1335e04a65060)\nPackage impersonates the bitcoinjs/bip39 project (author field set to 'bitcoinjs-lib') and ships a postinstall.js that runs on `npm install`. The script collects host/user identifiers and a curated list of sensitive environment variables (including NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_* keys, and wallet-related PRIVATE_KEY/MNEMONIC/SEED_PHRASE), enumerates ~/.ssh, reads ~/.npmrc and ~/.gitconfig, probes Chrome/Firefox profile artifacts and crypto wallet directories, and shells out to `npm whoami` and `git config`. The collected JSON is transmitted to two hardcoded destinations: the Telegram Bot API (bot token and chat_id 7231970337 embedded in the script) and a POST to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Exfiltration is delayed by a randomized setTimeout (1500 + rand*2000 ms) and the module re-exports./index.js to appear legitimate.\n","modified":"2026-08-05T01:49:45.137857945Z","published":"2026-08-05T00:53:35Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-011471","import_time":"2026-08-05T01:39:30.493022006Z","modified_time":"2026-08-05T00:53:35Z","sha256":"7f370f7bfdab3817c323daee33d8de48e5171c41dad3f1bff2f1335e04a65060","source":"amazon-inspector","versions":["2.3.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/bip39-mnemonic/v/2.3.1"}],"affected":[{"package":{"name":"@zzzgenesis00/bip39-mnemonic","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/bip39-mnemonic"},"versions":["2.3.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"8ff3ace595efd90d97570c02bfc3273fc408387719b07061d7b7c044ee149356","tlsh":"4fd161a612ea031c5952a9ad4b4f00251673e1033c20faf67ecc0f620f5e52cdab97ac"}],"package_integrity":[{"hashes":{"sha1":"ab91f9c4e573437f4bce8515ef6c13b7fdcbd16d","sha512_sri":"sha512-eqW6jBkvQovUwf+XnMW2swGiJGbfabXvJM+CLlAQrF7J3eh+BlDoy0nYb7F99wyPb2mG1f3oJokvWkkSuqi6nA=="},"filename":"bip39-mnemonic-2.3.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/bip39-mnemonic/MAL-2026-12030.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}