{"id":"MAL-2026-13214","summary":"Malicious code in @zzzcrypto/solana-spl-token (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6ceac45508e2f9506a082b2195d3bae4b046f096d11856d72ea53f784ad5992e)\n@zzzcrypto/solana-spl-token@0.4.0 is a typosquat/impersonation of @solana/spl-token (README self-describes as a 'drop-in replacement'; author metadata is set to 'solana-labs'). On module load, index.js enumerates the full process.env and augments it with hostname, username, homedir, platform, and cwd, base64-encodes the JSON payload, and sends it as an HTTPS GET to api.telegram.org/bot\u003credacted\u003e/sendMessage with chat_id=8969499041. A temporary flag file gates the beacon to once per host. Variable names are randomized (dmcp, uqxj, bhhs, _h, _flag) and the payload is base64-wrapped to hide the exfil body. If the real @solana/spl-token is not installed, the package falls back to a stub API exporting createWallet/generateMnemonic that returns random bytes rather than real key material. On typical developer and CI machines, process.env contains credentials such as AWS_*, GITHUB_TOKEN, and NPM_TOKEN, which are shipped off-host to the attacker's Telegram chat.\n","modified":"2026-08-05T16:50:19.388820137Z","published":"2026-08-05T15:32:40Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015739","import_time":"2026-08-05T16:13:38.714577941Z","modified_time":"2026-08-05T15:32:40Z","sha256":"6ceac45508e2f9506a082b2195d3bae4b046f096d11856d72ea53f784ad5992e","source":"amazon-inspector","versions":["0.4.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@zzzcrypto/solana-spl-token/v/0.4.0"}],"affected":[{"package":{"name":"@zzzcrypto/solana-spl-token","ecosystem":"npm","purl":"pkg:npm/%40zzzcrypto/solana-spl-token"},"versions":["0.4.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@zzzcrypto/solana-spl-token/MAL-2026-13214.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"5a58f9527691d4fe79312f255b37030bd8f239a7","sha512_sri":"sha512-cgNJ2tr33WJzziEOqQtvEyY+kjY4Veoy102YcCrbmb96zvBOXo0X21h96t8cQ3WeAbM86f9YX3zKbF0usv9tEA=="},"filename":"solana-spl-token-0.4.0.tgz"}],"evidence_files":[{"tlsh":"842179cc27f2bd8d16377592982f600bb27bc5b60488f614c564e1c37f705c85a16b94","path":"index.js","sha256":"963f4cb0eb93714a1f3571f6c031f997cb569a155f08d8dfcbaf349bf64746b2"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}