{"id":"MAL-2026-12031","summary":"Malicious code in @zzzgenesis00/ethers-wallet (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a206d278a371fdbb349d679797e7835b5e0ba40d1ac186b3287beb0a23540f09)\nThe package's postinstall.js runs automatically on `npm install` and harvests installer-owned secrets: it scrapes a curated env-var allowlist (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, PRIVATE_KEY, MNEMONIC, SEED_PHRASE, RPC API keys), enumerates ~/.ssh, reads ~/.npmrc and ~/.gitconfig, inventories Chrome/Firefox profile directories (cookies/login databases) and common crypto-wallet directories, and captures host identifiers via `npm whoami` and `git config user.email`. The collected profile is transmitted via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and POSTed as backup to a hardcoded serveo user-tunnel host (40f955f39128bd79-178-249-214-24.serveousercontent.com/collect). Package metadata (author `ethers-io`, homepage github.com/ethers-io/ethers-wallet) impersonates the ethers.js HD-wallet library while being published under the unrelated `@zzzgenesis00` scope, luring developers with wallet material into installing the stealer.\n","modified":"2026-08-05T01:49:46.073750322Z","published":"2026-08-05T00:59:03Z","database_specific":{"malicious-packages-origins":[{"versions":["6.13.5"],"id":"IN-MAL-2026-011475","import_time":"2026-08-05T01:39:30.64829407Z","modified_time":"2026-08-05T00:59:03Z","sha256":"a206d278a371fdbb349d679797e7835b5e0ba40d1ac186b3287beb0a23540f09","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/ethers-wallet/v/6.13.5"}],"affected":[{"package":{"name":"@zzzgenesis00/ethers-wallet","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/ethers-wallet"},"versions":["6.13.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/ethers-wallet/MAL-2026-12031.json","indicators":{"package_integrity":[{"filename":"ethers-wallet-6.13.5.tgz","hashes":{"sha512_sri":"sha512-FCP+La/WfvcDZgZPq3pG6TAX38LF2UZTMJLALuZaNpDbgFkkgiJ5imIQNzMHJbWLBXrj3P+h6fI8npJI9y5o4Q==","sha1":"bfee1dc1bce0226142e89de27e1e130943e61df1"}}],"evidence_files":[{"path":"postinstall.js","sha256":"dd752af518f3b5df8488ac0b0a0d13791dbc5aaf352a2b03a0c0a8c9cec0e7de","tlsh":"e0d1659712e703185c93e9ae879f10242a32d1073c51faf47ecd4b524f4d62c9af57a8"},{"path":"package.json","sha256":"a134da2de5af48f843c3332a27ba4951676d6539f848cf0340d0f30b354872bc","tlsh":"900176248510aa3329cc1b81a82a22e7b6325c478d90b82833eb054c878f67f1afe51c"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}