{"id":"MAL-2026-12087","summary":"Malicious code in @wethenorth12/bitcoin-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (34ac8cc76bddd60e41e530c9bb7cc74d902d3cb21a551db409bfdcac50a99cb8)\nOn require(), index.js reads the entire process.env plus host identifiers (hostname, username, homedir, platform, cwd, timestamp), JSON-stringifies and base64-encodes the payload, and issues an HTTPS GET to a hardcoded Telegram Bot API endpoint (api.telegram.org bot 7231970337, chat_id 8969499041). A tmpdir flag file gates one send per host. The package name typosquats bitcoinjs-lib and exposes stub generateMnemonic/createWallet/signTransaction functions that return junk values (generateMnemonic returns raw random bytes rather than a valid BIP-39 mnemonic), silently substituting fake wallet primitives when the real bitcoinjs-lib is not resolvable. Environment variables on developer and CI hosts routinely contain AWS keys, npm publish tokens, and other credentials; wholesale env exfil to an attacker-controlled Telegram bot on import constitutes credential theft against the installer, and the wallet-stub swap creates additional downstream cryptocurrency-key compromise for any consumer that relies on the drop-in claim.\n","modified":"2026-08-05T07:20:50.650053210Z","published":"2026-08-05T06:25:08Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["6.1.7"],"id":"IN-MAL-2026-013451","import_time":"2026-08-05T07:06:48.130766356Z","modified_time":"2026-08-05T06:25:08Z","sha256":"34ac8cc76bddd60e41e530c9bb7cc74d902d3cb21a551db409bfdcac50a99cb8"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/bitcoin-lib/v/6.1.7"}],"affected":[{"package":{"name":"@wethenorth12/bitcoin-lib","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/bitcoin-lib"},"versions":["6.1.7"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-WX4hAdJXzvYz82mrKueASUSd92bhUvh+q5pAwnZjFKybSxXMF3haLNUAPufRIMtNhuRIrtTgjgVu/fq/4e1FFg==","sha1":"f797188d3956aa9f7933498054b6846b3c0533f2"},"filename":"bitcoin-lib-6.1.7.tgz"}],"evidence_files":[{"path":"index.js","sha256":"b1dd78dd96c7e7a5beef3e123cefa214464d4640ebe983055e47ea2bab8eea00","tlsh":"4a2144c827b1f88e23726592643f610ab2abcae20848f751d5a9d1c72f741c889657cc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/bitcoin-lib/MAL-2026-12087.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}