{"id":"MAL-2026-12095","summary":"Malicious code in @wethenorth12/hd-key-generator (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0b2e832840746236ecbc71ba886ec793620dd508cd2a75eca04bd44e575cb03b)\n@wethenorth12/hd-key-generator markets itself as a drop-in replacement for the popular `hdkey` wallet library. On require, index.js reads the full process.env plus hostname, username, homedir, platform, and cwd, JSON-encodes and base64-encodes the payload, and sends it as a Telegram sendMessage GET to a hardcoded bot token with chat_id 8969499041 (api.telegram.org/bot\u003credacted\u003e/sendMessage). A tmp marker file is written to suppress repeated sends. Variable names in the file are obfuscated (ywek, icul, vwuh, _h, _flag) and the exfil body is base64-wrapped. The advertised wallet API (createWallet, signTransaction, generateMnemonic) returns non-functional stubs; the package's only real effect is credential harvesting. In developer and CI environments, process.env typically contains AWS_*, GITHUB_TOKEN, NPM_TOKEN, and other cloud/service credentials, all of which leave the installer's host to the attacker-controlled Telegram chat on first import.\n","modified":"2026-08-05T07:20:54.940727124Z","published":"2026-08-05T06:23:30Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T07:06:47.587640001Z","modified_time":"2026-08-05T06:23:30Z","sha256":"0b2e832840746236ecbc71ba886ec793620dd508cd2a75eca04bd44e575cb03b","source":"amazon-inspector","versions":["1.6.3"],"id":"IN-MAL-2026-013440"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/hd-key-generator/v/1.6.3"}],"affected":[{"package":{"name":"@wethenorth12/hd-key-generator","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/hd-key-generator"},"versions":["1.6.3"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"f8702540197ebac8dd4d30e085c94ecc54b6393cbe58c60efa80d93292d26dda","tlsh":"d12166c827f1f89d2272a551646f650fb3bbcaa20888eb20c598c4c37f701c899657d8"},{"sha256":"28df9a7ac415c2ee0f4c77420c005e58865205bc85e3e708bea67b02d26878c2","tlsh":"7cf09e3466613171605ba2cbfae360fa943680327210e578c9ee4c7ee153dca037f583","path":"README.md"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-CT+Y30sr81xF1Lb0t9eaPVYA4TVfkpucmhfRaeMjnRPdC+KD3/0JqRB8ssggQ5Ir9AeGEpSvOr30DfWxCA8f9Q==","sha1":"ed6c6a570e107461436362df5508b0730827d905"},"filename":"hd-key-generator-1.6.3.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/hd-key-generator/MAL-2026-12095.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}