{"id":"MAL-2026-12106","summary":"Malicious code in @wethenorth12/web3-provider-engine (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0f54c89c6e669f4a9e1e2939e09b5ac809507f98df451e239add607d417f394a)\nPackage name mimics MetaMask's official web3-provider-engine and its README advertises a drop-in replacement, but the exported API (connect/createWallet/generateMnemonic) is a hollow stub — generateMnemonic returns crypto.randomBytes(32).toString('hex') rather than a valid BIP-39 mnemonic, silently producing non-functional wallets. On module load via the declared main (index.js), the package reads the entire process.env object together with hostname, username, home directory, platform, cwd, and package identifiers, base64-encodes the JSON payload, and sends it in an HTTPS GET to a hardcoded Telegram Bot API endpoint (api.telegram.org, bot ID 7231970337, chat_id 8969499041). A marker file (.npi-\u003crandom\u003e) in the OS temp directory suppresses repeat sends per host. Bulk enumeration of process.env at import time harvests any secrets present in the installer's environment, including CI/CD tokens, cloud provider credentials, npm publish tokens, and database URLs.\n","modified":"2026-08-05T07:20:59.349212925Z","published":"2026-08-05T06:22:46Z","database_specific":{"malicious-packages-origins":[{"versions":["16.0.5"],"id":"IN-MAL-2026-013435","import_time":"2026-08-05T07:06:47.415012155Z","modified_time":"2026-08-05T06:22:46Z","sha256":"0f54c89c6e669f4a9e1e2939e09b5ac809507f98df451e239add607d417f394a","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/web3-provider-engine/v/16.0.5"}],"affected":[{"package":{"name":"@wethenorth12/web3-provider-engine","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/web3-provider-engine"},"versions":["16.0.5"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"0305f7089240d356edec86d841a4538ba38ecd0dc2cc27b4bb1783ae5072a580","tlsh":"f42196ad2bf1b44e12335991b86f260bb67fcba20484f620c1a5d1c37f301c84a557c8"}],"package_integrity":[{"filename":"web3-provider-engine-16.0.5.tgz","hashes":{"sha1":"eff0488c50d82cc99d1ff29db1d446933b9989e0","sha512_sri":"sha512-Wm0glV2Q8L8uJa5Chcp1MYSzSI/HGtxoKYd6HPrsx/GHDsuva+1z8nTv5ol0QX81WyhG5I0tJPoqm6s/qh8IKQ=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/web3-provider-engine/MAL-2026-12106.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}