{"id":"MAL-2026-12055","summary":"Malicious code in @zzzgenesis00/docker-api-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2417f0620e130c16865914c5f79fdff63bdda0daf3257955c8fd536ab894c1b1)\npostinstall.js runs automatically on npm install and enumerates installer-side secret stores including ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome and Firefox profile paths, and cryptocurrency wallet directories, and collects a hardcoded list of secret environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS keys, MNEMONIC, SEED_PHRASE, ETHEREUM_PRIVATE_KEY, and other API keys). The harvested profile is transmitted at install time via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and via HTTPS POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com (a serveo reverse-tunnel host), with a randomized 1.5-3.5s delay. package.json declares author `apocas` and repository `github.com/apocas/docker-api-client`, impersonating the maintainer of the legitimate dockerode/docker-modem packages; the scoped name `@zzzgenesis00/docker-api-client` is unrelated to that author.\n","modified":"2026-08-05T03:20:44.127727708Z","published":"2026-08-05T02:52:08Z","database_specific":{"malicious-packages-origins":[{"sha256":"2417f0620e130c16865914c5f79fdff63bdda0daf3257955c8fd536ab894c1b1","source":"amazon-inspector","versions":["2.0.2"],"id":"IN-MAL-2026-011963","import_time":"2026-08-05T03:12:04.484716586Z","modified_time":"2026-08-05T02:52:08Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/docker-api-client/v/2.0.2"}],"affected":[{"package":{"name":"@zzzgenesis00/docker-api-client","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/docker-api-client"},"versions":["2.0.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"docker-api-client-2.0.2.tgz","hashes":{"sha1":"68716daa88cd941dcb2ed905f24d4fc9e4fc6741","sha512_sri":"sha512-inDNdzsch1+U2q9r8idx9UuTtE+5/wu55dQ76SSUeyYCqbQU0nQ/xovqU2qX1ZdvgA4zdZKSoxmUHBXJsdGHNQ=="}}],"evidence_files":[{"tlsh":"74d1439a12f603186c92a9ae8f8f40241676d1173920fbf83fcd07514f4e53db6b57a8","path":"postinstall.js","sha256":"8598c30926f1aab97f9ab633cfea6989523295ae6012b500f68f55f299471135"},{"path":"package.json","sha256":"d74b7a7de01ba4b65f137a2a1df9389f94a9d67dbf929232c4526da3025695aa","tlsh":"a3012614c9612a732ad45b889c564182a7368c578a04bc0923ab42ac9b9f07b11fe14d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/docker-api-client/MAL-2026-12055.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}