{"id":"MAL-2026-13211","summary":"Malicious code in @zzzcrypto/bitcoin-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f9d633d3efb27db376be57d77ebbd808db458d088503adebe2f7ad7501281dd1)\nOn require(), index.js serializes process.env together with hostname, username, homedir, platform, cwd, and a timestamp, base64-encodes the JSON, and sends it via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id. A tmp flag file gates re-execution to reduce noise. The package name @zzzcrypto/bitcoin-lib and its README present it as a drop-in for bitcoinjs-lib, and the code attempts require('bitcoinjs-lib') to transparently proxy the real library's API when present so callers observe normal behavior; the internal identifier in the exfil payload is @wethenorth12/bitcoin-lib, and identifier names in the harvester are scrambled (kffr, xqyv, qzph, _h). Environment variables in developer and CI processes routinely contain credentials, API tokens, and cloud keys, so this constitutes credential and host-identity theft against any process that imports the package.\n","modified":"2026-08-05T16:50:16.332624209Z","published":"2026-08-05T15:32:11Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["6.1.7"],"id":"IN-MAL-2026-015736","import_time":"2026-08-05T16:13:38.227552807Z","modified_time":"2026-08-05T15:32:11Z","sha256":"f9d633d3efb27db376be57d77ebbd808db458d088503adebe2f7ad7501281dd1"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzcrypto/bitcoin-lib/v/6.1.7"}],"affected":[{"package":{"name":"@zzzcrypto/bitcoin-lib","ecosystem":"npm","purl":"pkg:npm/%40zzzcrypto/bitcoin-lib"},"versions":["6.1.7"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"b1dd78dd96c7e7a5beef3e123cefa214464d4640ebe983055e47ea2bab8eea00","tlsh":"4a2144c827b1f88e23726592643f610ab2abcae20848f751d5a9d1c72f741c889657cc"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-oDnNLw3grcwl6cjsJevIMsjU4uLyjdDfAXg/EyAOOZubbGnL3Zyc3/WK3/45hna+hPFhV4brD7BtV25KySB5og==","sha1":"94b362e2da35fa0a9c64263ab145113a0e73b2c5"},"filename":"bitcoin-lib-6.1.7.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzcrypto/bitcoin-lib/MAL-2026-13211.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}