{"id":"MAL-2026-12088","summary":"Malicious code in @wethenorth12/bitcoinjs-wallet (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (94f602036ff9f524298056528fbec6c58c9fb66ea2686bec418694b5854aeea4)\nOn require(), index.js collects the full process.env object together with hostname, username, home directory, platform, current working directory, and a timestamp, JSON-encodes and base64-encodes the payload, and issues an HTTPS GET to api.telegram.org/bot\u003ctoken\u003e/sendMessage with a hardcoded bot token and chat_id. A tmp-file flag suppresses re-sending. The package advertises itself as a 'Drop-in replacement for bitcoinjs-lib' under an unrelated scope and ships only stub wallet functions alongside this exfiltration payload, consistent with a typosquat lure targeting bitcoinjs-lib users. In modern development and CI environments, process.env routinely contains cloud credentials, npm/GitHub tokens, and database passwords, all of which are sent to the attacker-controlled Telegram chat on module load.\n","modified":"2026-08-05T07:20:51.097126474Z","published":"2026-08-05T06:24:40Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T06:24:40Z","sha256":"94f602036ff9f524298056528fbec6c58c9fb66ea2686bec418694b5854aeea4","source":"amazon-inspector","versions":["5.4.2"],"id":"IN-MAL-2026-013448","import_time":"2026-08-05T07:06:47.939782616Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/bitcoinjs-wallet/v/5.4.2"}],"affected":[{"package":{"name":"@wethenorth12/bitcoinjs-wallet","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/bitcoinjs-wallet"},"versions":["5.4.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-NaTj2ORja1/HDr9AvfSfgE4je3AYkD5VqMKiVJ4M9BRfpQMEaXTPoOAOYmhTtBHAD5/m5zdO2BJjGU+9FYJHog==","sha1":"3e4d74e82b4957f614894357e53b73713f10b5f1"},"filename":"bitcoinjs-wallet-5.4.2.tgz"}],"evidence_files":[{"sha256":"3d3afcdc0d19893d0b3b9448f5f98f669bb799388a036204fd12d688d871297c","tlsh":"182166dc27f1f94e22336142542f610ab2bbdae20488e661d5a4d0c76f741cc8d6578c","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/bitcoinjs-wallet/MAL-2026-12088.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}