{"id":"MAL-2026-12078","summary":"Malicious code in trezor-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (744ba5806b927aefbdd505acb44fb77a23bb71570d27d1ba17ec7642dcf17383)\ntrezor-lib@1.0.3 is a Trezor-lookalike npm package whose index.js, on first require(), harvests installer-side secrets and posts them to a hardcoded webhook.site inbox. The require-time payload reads $HOME/.env, ~/.npmrc, ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/id_ecdsa, ~/.config/solana/id.json, and ~/.ethereum/keystore, and enumerates dotfile directories for files matching wallet|key|secret|seed|mnemonic|keystore|private with.json/.pem extensions. The collected file contents are bundled with os.hostname() and os.userInfo().username into a JSON payload and sent via https.request to hostname webhook.site path /5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4. Execution is gated behind a Date.UTC(2026,7,6) activation timestamp with an in-source comment stating the delay is to avoid npm sandbox detection windows, so pre-activation-date installs see a no-op while real installers after that date trigger the harvester. The package name typosquats Trezor while its declared purpose is a generic utility library; the traced behavior is credential and wallet-secret theft, not any legitimate library function.\n\n## Source: ossf-package-analysis (d81bc24e9f56c5ca72558e331a2d0fae1d514c1c3fe26d275b5885c91a8a72f5)\nThe OpenSSF Package Analysis project identified 'trezor-lib' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-08-05T07:21:35.276156534Z","published":"2026-08-05T02:07:37Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"import_time":"2026-08-05T03:11:11.965231275Z","modified_time":"2026-08-05T02:07:37Z","sha256":"d81bc24e9f56c5ca72558e331a2d0fae1d514c1c3fe26d275b5885c91a8a72f5","source":"ossf-package-analysis"},{"import_time":"2026-08-05T07:06:47.075770828Z","modified_time":"2026-08-05T06:21:36Z","sha256":"0b822747067118a36f2ac26bf830e9fc8bbbdc26fa77216a4366184d40ae69c7","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-013427"},{"import_time":"2026-08-05T07:06:45.88119522Z","modified_time":"2026-08-05T06:18:16Z","sha256":"5ed7fc8451b4d2196ad538dc1854d23504faab52e30eafa59c253e69bb5f2a67","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-013404"},{"sha256":"6af4bb60075c729a6f582ea56179dc42fb9e5c89b73d0ef9cea1c38f3ae93fd3","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-013421","import_time":"2026-08-05T07:06:46.857599012Z","modified_time":"2026-08-05T06:20:48Z"},{"id":"IN-MAL-2026-013397","import_time":"2026-08-05T07:06:45.443800605Z","modified_time":"2026-08-05T06:17:13Z","sha256":"744ba5806b927aefbdd505acb44fb77a23bb71570d27d1ba17ec7642dcf17383","source":"amazon-inspector","versions":["1.0.3"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/trezor-lib/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/trezor-lib/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/trezor-lib/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/trezor-lib/v/1.0.3"}],"affected":[{"package":{"name":"trezor-lib","ecosystem":"npm","purl":"pkg:npm/trezor-lib"},"versions":["1.0.0","1.0.2","1.0.1","1.0.3"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"2f98ab95e05663b01db7b77b41a6c7a1564f59ce","sha512_sri":"sha512-7z+z/W/nKR4ohx4lo7c3wFngmrnOWxoUrMkWGb8JoYsmzk9yL+qLgvSe/qPmya5HiUU4okzXwC8zX2KTvR2Qeg=="},"filename":"trezor-lib-1.0.0.tgz"}],"evidence_files":[{"path":"postinstall.js","sha256":"fe32f577c0be956d68eec04bf5a29f6cd3a3a495d638421ae4d9ef92f74f83c2","tlsh":"153120e045e61630555736e8852b2200b173f29334469ec87acc5b118f1dc6846a7bfc"},{"sha256":"060fbe5c94d48ecc2e5f4eca8cd98dfe0e1d518d8ee96a832aa2df16ac7bb57e","tlsh":"c1d02b102f12a67324d42f690923825936320c1e4185742d13f79054828f2b31afbb0e","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/trezor-lib/MAL-2026-12078.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}