{"id":"MAL-2026-12112","summary":"Malicious code in mnemonic-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dc209736a2c44e541e224030a4c0bd7145bb77a17fa66504cd96beedc75ce6f4)\nindex.js executes an IIFE at require-time that reads installer-owned secret files (.env,.npmrc, ~/.aws/credentials, ~/.ssh/id_rsa, id_ed25519, id_ecdsa, Solana id.json, Ethereum keystore) and recursively scans home dotdirectories for files matching /wallet|key|secret|seed|mnemonic|keystore|private/. The harvested contents are combined with os.hostname() and os.userInfo().username into a single JSON body and POSTed over HTTPS to a hardcoded webhook.site URL (path /5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4). The payload is gated by a Date.UTC(2026,7,6) activation check, with in-source comments describing the delay as evasion of npm sandbox detection windows. The package name suggests a mnemonic utility, but the shipped code performs no such function — its only behavior is credential and wallet-secret exfiltration.\n","modified":"2026-08-05T07:21:18.216190838Z","published":"2026-08-05T06:18:00Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T06:18:08Z","sha256":"1fa35d474395d73750ae91e7fe420051657623e9a10c517cb06f184f23bc4310","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-013403","import_time":"2026-08-05T07:06:45.804246772Z"},{"versions":["1.0.2"],"id":"IN-MAL-2026-013402","import_time":"2026-08-05T07:06:45.758800806Z","modified_time":"2026-08-05T06:18:00Z","sha256":"dc209736a2c44e541e224030a4c0bd7145bb77a17fa66504cd96beedc75ce6f4","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-013418","import_time":"2026-08-05T07:06:46.663497335Z","modified_time":"2026-08-05T06:20:19Z","sha256":"2cbe05c633f1390b0beffc89dcd60b0ba64f78e9f6b2e32a9f428ac88a295c3e"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/mnemonic-utils/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/mnemonic-utils/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/mnemonic-utils/v/1.0.0"}],"affected":[{"package":{"name":"mnemonic-utils","ecosystem":"npm","purl":"pkg:npm/mnemonic-utils"},"versions":["1.0.1","1.0.2","1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"9e2130d200f59b65268a0a9ad8182700527769676c0aacc17efc6e874f888940e37bfc","path":"postinstall.js","sha256":"720a192a5f8902b99c23e21e27f721d723c455d2302d30a186187189c8cb9288"}],"package_integrity":[{"filename":"mnemonic-utils-1.0.1.tgz","hashes":{"sha1":"1797dee212fc833b81f2f21d45844d46e996673e","sha512_sri":"sha512-edkJXoPz81Im7guXBW4WedNi7BG/ro6VxIFimjSqRODwJswuP7Z43Y7F7+rey8aH99fmhtRnBCh+sSYz61GVzg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mnemonic-utils/MAL-2026-12112.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}