{"id":"MAL-2026-12498","summary":"Malicious code in wagmi-react (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6285993305d8ff9bbf69804dcbf929539b6f48c2ef1b1ca6e5c723150c5565ee)\nThe package impersonates the wagmi/viem wallet API surface (exporting createWalletClient, parseAccount, and a WalletClient constructor) and, when a caller instantiates WalletClient with a privateKey, serializes the private key together with os.hostname() and os.userInfo().username and POSTs the JSON body to the hardcoded endpoint https://enjbyg3xk8l.x.pipedream.net/k. Any caller passing a wallet private key through the advertised API silently transmits that key to an attacker-controlled Pipedream webhook, enabling full wallet compromise. The package name and API shape mimic the legitimate wagmi/viem ecosystem to capture keys from developers who mistype or mis-select the dependency.\n","modified":"2026-08-05T13:36:26.077869037Z","published":"2026-08-05T12:58:28Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014830","import_time":"2026-08-05T13:08:49.765223272Z","modified_time":"2026-08-05T12:58:28Z","sha256":"6285993305d8ff9bbf69804dcbf929539b6f48c2ef1b1ca6e5c723150c5565ee","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wagmi-react/v/1.0.0"}],"affected":[{"package":{"name":"wagmi-react","ecosystem":"npm","purl":"pkg:npm/wagmi-react"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"9656fdc46879ba1856a53765902d30921ce8428fa0d623005a5fd2217722c7e7","tlsh":"4c011ae153f47eee59d14726d410d2ddd6b16d9ca2050df4ab56e3cfd5c44900718934"}],"package_integrity":[{"filename":"wagmi-react-1.0.0.tgz","hashes":{"sha1":"8bed4f84d15f1a0667b8d0e629ae9f3a9419850b","sha512_sri":"sha512-YqTDFhOyZXS/NnQ0kN9Boh0kP+RQK4Nc1yOEBKNc3mAHlg7qiJK3tG8WxNrn4PWXUTEz3eweIMKRw0BaQLPdtw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wagmi-react/MAL-2026-12498.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}