{"id":"MAL-2026-12123","summary":"Malicious code in @zzzgenesis00/solana-spl-token (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (985d4d8e5069084334daa08512249314d36d9fa8662adef050021c2400dacbdd)\n@zzzgenesis00/solana-spl-token@0.4.0 impersonates the Solana SPL Token package and runs postinstall.js on `npm install`. The script harvests host identity, reads ~/.ssh, ~/.npmrc, and ~/.gitconfig, probes Chrome/Firefox profiles and cryptocurrency wallet directories, and scrapes ~40 credential-shaped environment variables including NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, MNEMONIC, SEED_PHRASE, SOLANA_PRIVATE_KEY, and Helius/Infura/Alchemy API keys. It shells out via child_process.execSync to run `npm whoami` and `git config --global user.email`, capturing the installer's npm login identity alongside the stolen ~/.npmrc auth token. The collected JSON is exfiltrated over two channels: the Telegram Bot API (hardcoded bot token, chat_id) at api.telegram.org, and an HTTP POST to 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect (a serveo tunnel). Execution is delayed with setTimeout and random jitter to obscure the beacon.\n","modified":"2026-08-05T10:05:40.071048043Z","published":"2026-08-05T08:43:26Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T09:28:05.437416148Z","modified_time":"2026-08-05T08:43:26Z","sha256":"985d4d8e5069084334daa08512249314d36d9fa8662adef050021c2400dacbdd","source":"amazon-inspector","versions":["0.4.0"],"id":"IN-MAL-2026-014390"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/solana-spl-token/v/0.4.0"}],"affected":[{"package":{"name":"@zzzgenesis00/solana-spl-token","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/solana-spl-token"},"versions":["0.4.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"a302faed20974152bb9637ea56ef49f5ee7e907436d8f11ed8e368938b85a05e","tlsh":"20d161da12e603186892b9ad8b4f40141a37d5033c20faf47ecd8b154f4e93c9bb67a8"}],"package_integrity":[{"hashes":{"sha1":"4c1c68396ec4e7022fe71c8b9591bb2c53540483","sha512_sri":"sha512-lkp+3FSpLvHhqnOjCGulP+i3VfQBISs5F73wJisYPKpq3nWULBJWHIPsT5E4qQK9aeZfpR8bmJD6le+1Doce5Q=="},"filename":"solana-spl-token-0.4.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/solana-spl-token/MAL-2026-12123.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}