{"id":"MAL-2026-12101","summary":"Malicious code in @wethenorth12/solana-wallet-adapter (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (14e7d05f22a60d86ce4aea030108a6f50a69b85ce9bb0219eb59fbe2dbc3bbb2)\nOn require(), index.js JSON-encodes the full process.env plus hostname, username, homedir, platform, cwd, and package metadata, base64-encodes the payload, and sends it as a Telegram Bot API sendMessage GET request to a hardcoded bot token and chat_id (8969499041). A marker file in the OS tmpdir gates the beacon to fire once per host. The package impersonates @solana/wallet-adapter-base: the author field is spoofed as 'anza-xyz', the README advertises a 'drop-in replacement', and the module attempts to require the real @solana/wallet-adapter-base and re-export it so consumers see a working facade while the exfiltration runs silently. Developer and CI environments routinely carry AWS_*, GITHUB_TOKEN, NPM_TOKEN, and other credential-shaped variables, so a full env dump to an attacker endpoint is credential theft against the installer.\n","modified":"2026-08-05T07:20:57.744527108Z","published":"2026-08-05T06:23:37Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-013441","import_time":"2026-08-05T07:06:47.619911889Z","modified_time":"2026-08-05T06:23:37Z","sha256":"14e7d05f22a60d86ce4aea030108a6f50a69b85ce9bb0219eb59fbe2dbc3bbb2","source":"amazon-inspector","versions":["0.18.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/solana-wallet-adapter/v/0.18.0"}],"affected":[{"package":{"name":"@wethenorth12/solana-wallet-adapter","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/solana-wallet-adapter"},"versions":["0.18.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/solana-wallet-adapter/MAL-2026-12101.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"5bb91c00520fe8741c66fc5843a13205cfc7fed1","sha512_sri":"sha512-JBb33M+PnytGyROM9FG/rrLlZ8vj8DuSQflSFkdFqD8bUlpTz1brALfQVBh7vZHMSdsDBba/MgWI5pP8+ma18Q=="},"filename":"solana-wallet-adapter-0.18.0.tgz"}],"evidence_files":[{"tlsh":"4c21798827f1fd4d52736282593f610ff3bbc9a1184cea20d5a8e1872f391d89b25798","path":"index.js","sha256":"ae84fb2789d1c8b20799e6ff9a41fa4ab8e100a617116d0e2eb053ce8f3d50f6"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}