{"id":"MAL-2026-12122","summary":"Malicious code in @zzzgenesis00/near-api (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b5e6b0c979c111a298e5a63a60690d41751672624107b847cf342c49b3b8843f)\nThe package's postinstall.js lifecycle script runs on `npm install` and collects installer-side secrets: it enumerates a hardcoded list of credential-shaped environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, MNEMONIC, SEED_PHRASE, ETHEREUM_PRIVATE_KEY, and other API keys), reads ~/.ssh, ~/.npmrc, and ~/.gitconfig, probes Chrome/Firefox profiles and cryptocurrency wallet directories (.metamask,.exodus,.electrum,.ethereum,.solana), and runs `npm whoami` and `git config`. The collected bundle is POSTed to two hardcoded attacker-controlled destinations: api.telegram.org via a hardcoded bot token and chat_id, and a Serveo reverse-tunnel host at 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Execution is deferred with `setTimeout(1500 + Math.random()*2000)` and errors are swallowed; variable names are obfuscated (_jag, _jui, _tk, _ch) and the script is labeled 'postinstall environment verification' as cover. `module.exports = require('./index.js')` provides passthrough so consumers see near-api-like behavior. The package name typosquats NEAR Protocol's official near-api package.\n","modified":"2026-08-05T10:05:39.883451693Z","published":"2026-08-05T08:43:33Z","database_specific":{"malicious-packages-origins":[{"sha256":"b5e6b0c979c111a298e5a63a60690d41751672624107b847cf342c49b3b8843f","source":"amazon-inspector","versions":["3.0.1"],"id":"IN-MAL-2026-014391","import_time":"2026-08-05T09:28:05.564432768Z","modified_time":"2026-08-05T08:43:33Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/near-api/v/3.0.1"}],"affected":[{"package":{"name":"@zzzgenesis00/near-api","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/near-api"},"versions":["3.0.1"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"f456896e33124201d714f1148de543093ae569ae","sha512_sri":"sha512-3r5qOw7Pf/tSbBj6oH3+dM8hF/yRTO4Os+EXy3iA6Tb5lLV7PfIywAxHxsO1J4spPAmYz42+QWpDgal6aVQvag=="},"filename":"near-api-3.0.1.tgz"}],"evidence_files":[{"path":"postinstall.js","sha256":"1d869b1070fdd032692bdca11891d6f76de286bace53b42535fe1a0e759aa822","tlsh":"add1569612e7036978a6b9ef4b8f00241636e1073c18faf43ecd47624f4d52c9ab57b8"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/near-api/MAL-2026-12122.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}