{"id":"MAL-2026-12125","summary":"Malicious code in @zzzgenesis00/web3-utils-crypto (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c5f75dc3a679eaa0579352bb4d345acb84247d70f4e4db06e5de04ff6d20f4e5)\n@zzzgenesis00/web3-utils-crypto ships a postinstall.js that runs automatically on npm install and harvests installer-side secrets and host data. The script reads ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile artifacts, wallet directory presence, and enumerates a large list of credential-shaped environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, PRIVATE_KEY, MNEMONIC, SEED_PHRASE, ETHEREUM_PRIVATE_KEY, and similar), together with hostname, username, homedir, platform/arch, cpu/mem, and cwd. It also invokes `npm whoami`. The collected JSON is transmitted to a hardcoded Telegram bot endpoint (api.telegram.org/bot\u003credacted\u003e/sendMessage?chat_id=7231970337) and POSTed to a serveo.net SSH-tunnel subdomain at 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Identifiers in the payload script are obfuscated (_syt, _bqi, _okl, _tk, _ch, _ex) and framed with cover-story comments (`postinstall environment verification`, `Legitimate module passthrough`); package.json impersonates the ChainSafe organization via a spoofed author field and homepage pointing at github.com/chainSafe/web3-utils-crypto.\n","modified":"2026-08-05T10:05:41.000178081Z","published":"2026-08-05T08:43:43Z","database_specific":{"malicious-packages-origins":[{"sha256":"c5f75dc3a679eaa0579352bb4d345acb84247d70f4e4db06e5de04ff6d20f4e5","source":"amazon-inspector","versions":["1.10.4"],"id":"IN-MAL-2026-014392","import_time":"2026-08-05T09:28:05.721981546Z","modified_time":"2026-08-05T08:43:43Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzgenesis00/web3-utils-crypto/v/1.10.4"}],"affected":[{"package":{"name":"@zzzgenesis00/web3-utils-crypto","ecosystem":"npm","purl":"pkg:npm/%40zzzgenesis00/web3-utils-crypto"},"versions":["1.10.4"],"database_specific":{"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"16c9d2c101e5a52adf1155cc86c9f768a8003232b6925b9615630602e4236f8b","tlsh":"6cd1959612e603686892b9ae874f50151672d1033c20fbf97fdc1b514f4e52cdaf57b8"}],"package_integrity":[{"filename":"web3-utils-crypto-1.10.4.tgz","hashes":{"sha1":"5a645e4536ce2abb931f06dfbbd2f620cdfda3a1","sha512_sri":"sha512-nWnXXDpH61j9IcfaEuF4/IMuQCGnk641Lfr88zwyv5CBVqhNSP7P1qMo00FQIIzvF2YzTCOsxhv++OJiI5zupQ=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzgenesis00/web3-utils-crypto/MAL-2026-12125.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}