{"id":"MAL-2026-12113","summary":"Malicious code in python-bitcoinlib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cfb9c83260c4fb83a678636e1e1c028f2aff3e3c0a0ac13728cfa2056a13389f)\nThis npm package, published under the well-known PyPI name `python-bitcoinlib`, ships a `postinstall.js` lifecycle script that runs automatically on `npm install`. The script reads classic installer secret paths including `~/.ssh/id_rsa`, `~/.aws/credentials`, `~/.npmrc`, `.env` files, and Solana/Ethereum wallet keystores (`~/.config/solana/id.json`), and additionally walks dotdirs under $HOME for files whose names match wallet/key/secret/seed/mnemonic/keystore/private patterns. The collected file contents, together with `os.hostname()` and `os.userInfo()`, are POSTed via `https.request` to a hardcoded webhook.site collector at `https://webhook.site/5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4`. The package name collides with the established PyPI `python-bitcoinlib` project but ships unrelated code on npm, indicating deliberate ecosystem-confusion typosquatting rather than a legitimate port.\n","modified":"2026-08-05T07:21:24.336009883Z","published":"2026-08-05T06:18:23Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T07:06:45.92131259Z","modified_time":"2026-08-05T06:18:23Z","sha256":"0b40d55f884f1f26d7e0c5b6e21c5d2c3e419ae844f867b6b9cfc73d99f0dc4a","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-013405"},{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-013414","import_time":"2026-08-05T07:06:46.415512564Z","modified_time":"2026-08-05T06:19:42Z","sha256":"2feaa9ed505ac89313fee83925ae8c3364477c8a468d84810275c7532b92832a"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-013426","import_time":"2026-08-05T07:06:47.036834562Z","modified_time":"2026-08-05T06:21:28Z","sha256":"9e6e2d9915baad022b788cee95aed5c00113d2701ca0c690c25ec55016241555"},{"modified_time":"2026-08-05T06:18:33Z","sha256":"cfb9c83260c4fb83a678636e1e1c028f2aff3e3c0a0ac13728cfa2056a13389f","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-013406","import_time":"2026-08-05T07:06:46.038443933Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/python-bitcoinlib/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/python-bitcoinlib/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/python-bitcoinlib/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/python-bitcoinlib/v/1.0.2"}],"affected":[{"package":{"name":"python-bitcoinlib","ecosystem":"npm","purl":"pkg:npm/python-bitcoinlib"},"versions":["1.0.3","1.0.1","1.0.0","1.0.2"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"e89f89726d0e20dccbae6ea5512d2b0a032b00f58a037976a384905e6e4d53b1","tlsh":"152163d220f22721169b168a982a27006377a5672c0bdc807efc1b871f8dc550666bfc"}],"package_integrity":[{"filename":"python-bitcoinlib-1.0.3.tgz","hashes":{"sha1":"6caa2ac25662de85e8387545afa6fe20fcfddb6e","sha512_sri":"sha512-ZXi1PA1KAMt7tNexDttLOjBtRB8lcLCf90IUWqtpsYgTRlv1ivyJ6t3vcUYcTRGsHI1h6eIGYHEqWXXMG1/1gA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/python-bitcoinlib/MAL-2026-12113.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}