{"id":"MAL-2026-12100","summary":"Malicious code in @wethenorth12/solana-spl-token (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7dde46db2fbc17fae2957070f85bc43fdb1d265444f2e5adc936faa6f82e96e2)\n@wethenorth12/solana-spl-token is a typosquat of the legitimate @solana/spl-token package. On module load, index.js collects hostname, username, home directory, platform, current working directory, and the entire process.env, base64-encodes the JSON payload, and sends it via HTTPS GET to a hardcoded Telegram Bot API endpoint (bot id 7231970337, chat_id 8969499041). A flag file in the OS tmpdir prevents re-sending on subsequent requires. The package additionally ships stub wallet primitives (createWallet, generateMnemonic, signTransaction) that return random or no-op values when the real @solana/spl-token is not present, while marketing itself in the README as a drop-in replacement. Environment variables in CI and developer machines routinely contain credentials such as AWS_*, GITHUB_TOKEN, NPM_TOKEN, and database connection strings, all of which leave the installer's host to an author-controlled Telegram destination on any require of this package.\n","modified":"2026-08-05T07:20:56.795663527Z","published":"2026-08-05T06:24:04Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T06:24:04Z","sha256":"7dde46db2fbc17fae2957070f85bc43fdb1d265444f2e5adc936faa6f82e96e2","source":"amazon-inspector","versions":["0.4.0"],"id":"IN-MAL-2026-013444","import_time":"2026-08-05T07:06:47.780643385Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/solana-spl-token/v/0.4.0"}],"affected":[{"package":{"name":"@wethenorth12/solana-spl-token","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/solana-spl-token"},"versions":["0.4.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"solana-spl-token-0.4.0.tgz","hashes":{"sha1":"3874c9ddd0cc9e7853784a69bf5c2056a128e04c","sha512_sri":"sha512-/yKFe4vbCmRVhOMEREFP1ZNgz9HODqZZXPM5CayWAwG0f0st5oMdscUFUc5EWtJAx/X5O/W0VHraIT1zcydVcg=="}}],"evidence_files":[{"tlsh":"842179cc27f2bd8d16377592982f600bb27bc5b60488f614c564e1c37f705c85a16b94","path":"index.js","sha256":"963f4cb0eb93714a1f3571f6c031f997cb569a155f08d8dfcbaf349bf64746b2"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/solana-spl-token/MAL-2026-12100.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}