{"id":"MAL-2026-12099","summary":"Malicious code in @wethenorth12/playwrite (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8e208f50bb22bacadd2c6debf8e973a50ba3a59db74e9c618fa28202eac96a64)\n@wethenorth12/playwrite is a typosquat of the popular 'playwright' package. On require(), index.js collects process.env, hostname, username, homedir, platform, cwd, and package metadata, JSON-serializes and base64-encodes the payload, then transmits it via an HTTPS GET to a hardcoded Telegram Bot API sendMessage endpoint (bot 7231970337, chat_id 8969499041) at api.telegram.org. A flag file in tmpdir suppresses re-runs. The module lazily attempts to require the real 'playwright' and otherwise exposes stub wallet/browser APIs (createWallet, generateMnemonic, signTransaction) that return non-functional values, serving purely as a delivery vehicle. Environment variables on developer and CI hosts routinely contain API tokens, cloud credentials, and CI secrets, all of which leave the installer's machine on import.\n","modified":"2026-08-05T07:20:56.534535753Z","published":"2026-08-05T06:23:53Z","database_specific":{"malicious-packages-origins":[{"versions":["1.48.0"],"id":"IN-MAL-2026-013443","import_time":"2026-08-05T07:06:47.741027282Z","modified_time":"2026-08-05T06:23:53Z","sha256":"8e208f50bb22bacadd2c6debf8e973a50ba3a59db74e9c618fa28202eac96a64","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/playwrite/v/1.48.0"}],"affected":[{"package":{"name":"@wethenorth12/playwrite","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/playwrite"},"versions":["1.48.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"11e720930e3fbc3057455466abdee00c3b0e3875b00fa1032a18edacdd335b7f","tlsh":"8b2133cc37f1f48e2273e192aa6f650bb6bbc9e10488e710e5a4d1c32fb41cc9955798"}],"package_integrity":[{"filename":"playwrite-1.48.0.tgz","hashes":{"sha512_sri":"sha512-IYNlYtUEEYSpmc5YWfJu9GygbE2fRhQLeoLAg+cxz0u2kv0PSsaCNkQOFXh3EUySMEao1lhtyHMGiRW+JreVvg==","sha1":"7a5831ff311194a91d97641576cc919c339b46f1"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/playwrite/MAL-2026-12099.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}