{"id":"MAL-2026-12121","summary":"Malicious code in @zzzgenesis00/hd-key-generator (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6d1bce1ae0778169c4e5fb37721dfcc052c984efc60a257166adb4d20e2d39e5)\n@zzzgenesis00/hd-key-generator ships a postinstall.js that runs automatically on npm install. It enumerates ~/.ssh, ~/.npmrc, ~/.gitconfig, browser profile artifacts (Chrome/Firefox cookies, Login Data, key4.db), and cryptocurrency wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum), and scrapes environment variables shaped as credentials (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, *_PRIVATE_KEY, MNEMONIC, SEED_PHRASE, API keys). The collected data is transmitted via two hardcoded channels: an HTTPS GET to api.telegram.org bot sendMessage using an embedded bot token and chat_id, and an HTTPS POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com. The payload is self-labeled as 'postinstall environment verification', uses cryptic identifiers (_cgn, _qik, _gso, _cp, _ht, _tk, _ch, _co, _ex), and is triggered via setTimeout with random jitter to obscure execution. index.js is a thin wrapper that re-exports the legitimate 'hdkey' module when present, providing a typosquat-style cover for HD-wallet developers while the stealer runs.\n","modified":"2026-08-05T10:05:38.924571696Z","published":"2026-08-05T08:42:59Z","database_specific":{"malicious-packages-origins":[{"versions":["1.6.3"],"id":"IN-MAL-2026-014387","import_time":"2026-08-05T09:28:05.166181612Z","modified_time":"2026-08-05T08:42:59Z","sha256":"6d1bce1ae0778169c4e5fb37721dfcc052c984efc60a257166adb4d20e2d39e5","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/hd-key-generator/v/1.6.3"}],"affected":[{"package":{"name":"@zzzgenesis00/hd-key-generator","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/hd-key-generator"},"versions":["1.6.3"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"ff6ffdeaf72d49c2898a142ff9ffd50ef7fd62730bbcb4ab641e6ff08a9b4ccb","tlsh":"80d164e323ea23186896b9ae474f40145632d2533810faf43fde1716af4d93c97b57a8"},{"tlsh":"8d119c922bf2f2140bc5f0a5d563c04be5b8e99305ac6229f64d792777f8548c0b1dd4","path":"index.js","sha256":"82d7b06c99e710f301f4a6dcf646fab500324f88297278917b36fb0e4f81efce"}],"package_integrity":[{"hashes":{"sha1":"5c0c662c00ff80d8568a7311b4952682e3d7e895","sha512_sri":"sha512-pBjowAY3mqQxzfags3RwOCluA1wkZTZBxA2NJfErBpez9GHNWQQ9URVRCY3uWUWKWlbd3PGD4AV8bth4PKa07g=="},"filename":"hd-key-generator-1.6.3.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/hd-key-generator/MAL-2026-12121.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}