{"id":"MAL-2026-12118","summary":"Malicious code in @zzzgenesis00/bitcoin-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (742be73b4f635f669a2c8191ddc90c46150e9d92ca432e5045c570fc0163f439)\n@zzzgenesis00/bitcoin-lib 6.1.7 runs a postinstall.js at npm install time that harvests installer-owned secrets and exfiltrates them to attacker-controlled destinations. The script enumerates ~/.ssh, reads ~/.npmrc and ~/.gitconfig, inventories Chrome/Firefox cookie and login stores, scans cryptocurrency wallet directories (.bitcoin,.ethereum,.metamask, Exodus, Electrum, and others), and captures a curated list of credential-shaped environment variables including NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, *_PRIVATE_KEY, MNEMONIC, and SEED_PHRASE. Collected data is JSON-serialized and sent, after a short setTimeout delay, via GET to api.telegram.org/bot\u003cTOKEN\u003e/sendMessage with a hardcoded chat_id and via POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com. The package.json falsely attributes authorship to 'bitcoinjs' and points the repository at github.com/bitcoinjs/bitcoin-lib, impersonating the well-known bitcoinjs organization while shipping under the unrelated @zzzgenesis00 scope.\n","modified":"2026-08-05T10:05:37.626573137Z","published":"2026-08-05T08:43:51Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["6.1.7"],"id":"IN-MAL-2026-014393","import_time":"2026-08-05T09:28:05.804335414Z","modified_time":"2026-08-05T08:43:51Z","sha256":"742be73b4f635f669a2c8191ddc90c46150e9d92ca432e5045c570fc0163f439"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/bitcoin-lib/v/6.1.7"}],"affected":[{"package":{"name":"@zzzgenesis00/bitcoin-lib","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/bitcoin-lib"},"versions":["6.1.7"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"eddbc21f7d2e50e6e35f4d1e3a526603bdf7ff6ec84a2a9dce677e4839aa22b5","tlsh":"6ed1539212e613186893e9af4b8f00141632d1473814fff53ecd57564f4e56c9bf6ba8","path":"postinstall.js"},{"path":"package.json","sha256":"07c26bc6f2e65528ae3309d84a21667bf10935106e73cec2c89b9f140fa35ade","tlsh":"850149a0d9601d332be82a816c2a418b76229c8f4c04bc2a33e7411c4f5d0bf1dfd12c"}],"package_integrity":[{"filename":"bitcoin-lib-6.1.7.tgz","hashes":{"sha1":"32f2c773ab92b6c9d3975aeb940c664dcf42506e","sha512_sri":"sha512-e3cRryjlWvmJLrfjAZGgDI0cuT2xPjzc9h5x0SyBKJD6fQvnaaxp6dSsNpiQs405oWTkigTirt9yCd6j3mL7PQ=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/bitcoin-lib/MAL-2026-12118.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}