{"id":"MAL-2026-12109","summary":"Malicious code in bip32-js (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (115345055f99da651c7816286c6b076dbacdd2b659f466dded1a541b289e8c2d)\nbip32-js is a typosquat of the legitimate bip32 crypto library. Its index.js is an empty stub (module.exports = {}); the package's only functional code is a postinstall hook that runs automatically on npm install. The hook reads classic installer-owned secret paths —.env files, ~/.npmrc, ~/.aws/credentials, ~/.aws/config, ~/.ssh/id_rsa, id_ed25519, id_ecdsa, Solana ~/.config/solana/id.json, Ethereum keystores, and ~/.gitconfig — and additionally scans hidden home subdirectories for files matching wallet, seed, mnemonic, key, and keystore patterns. It packages the collected file contents together with os.hostname(), os.userInfo().username, and a timestamp, and POSTs the JSON body via https.request to the hardcoded endpoint https://enxhcjpo5ev.x.pipedream.net/c, an author-controlled Pipedream request-bin. The package.json also declares a suspicious dependency entry \"self\":\"\" alongside a wildcard pin on the real bip32 package.\n","modified":"2026-08-05T07:21:03.824370918Z","published":"2026-08-05T06:19:15Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-013415","import_time":"2026-08-05T07:06:46.510226529Z","modified_time":"2026-08-05T06:19:53Z","sha256":"115345055f99da651c7816286c6b076dbacdd2b659f466dded1a541b289e8c2d","source":"amazon-inspector","versions":["1.0.1"]},{"sha256":"a19219372b5173cab05ed75eeab472404c3750eac6e3b3034a2ea02f4a0c0874","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-013411","import_time":"2026-08-05T07:06:46.274040404Z","modified_time":"2026-08-05T06:19:15Z"},{"id":"IN-MAL-2026-013431","import_time":"2026-08-05T07:06:47.236586338Z","modified_time":"2026-08-05T06:22:11Z","sha256":"f4b058369b7442f4041d4372cc22e942c8fc1c0e4cc93f7c686751136982216e","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bip32-js/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bip32-js/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bip32-js/v/1.0.0"}],"affected":[{"package":{"name":"bip32-js","ecosystem":"npm","purl":"pkg:npm/bip32-js"},"versions":["1.0.1","1.0.2","1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bip32-js/MAL-2026-12109.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"f54134d505df162154476bd8862b31107277e2d7344aa9c43e9c6b198f1d8384a5affc","path":"postinstall.js","sha256":"cb89d25cb941a6c4f7b12d049518b8756e9a4ce84ddaedb89c225795487ca171"},{"path":"package.json","sha256":"6d747abbf5377aca2e98a70705733d87926145f18f714cf3ef89eb777f8426aa","tlsh":"ffd02b501a5afa704ffd4fdd5c7ad97d08de520004cc853847e74078ca9e39e884d42e"}],"package_integrity":[{"hashes":{"sha1":"b988afaaabb8c9536240b6b428cbfe5c4acb439e","sha512_sri":"sha512-tlp6vJjmqUuA+ZtgU4DdLU80PzFgYR6PVaJVkGC++bGvOPyTIIMPsWevsrZwuPXcw1T20LwGa2nHg5BrmMwgFg=="},"filename":"bip32-js-1.0.1.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}