{"id":"MAL-2026-13737","summary":"Malicious code in @openzeppelin-4/contracts (npm)","details":"@openzeppelin-4/contracts is a malicious npm package published by npm account `mssjeep843` that impersonates OpenZeppelin's `@openzeppelin/contracts` (the v4 line) via the look-alike scope `@openzeppelin-4`, falsely describing itself as a \"compatibility distribution\". It ships no Solidity contracts — only an install-time payload (index.js) run via preinstall/postinstall that harvests credential-shaped environment variables and reads and exfiltrates SSH private keys, cloud credentials (AWS/GCP/Kubernetes/Docker), Solana/Anchor/NEAR/Sui wallet keys, Foundry keystores, `.git-credentials` and local `.env` files to `https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09`. It is one of a series of DeFi/crypto impersonation packages from the same account sharing this webhook.site endpoint, which also squat Aerodrome Finance, Camelot AMM, Euler EVC, BoringVault and Uniswap Permit2.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2841eb854dad391b8cf3d290704a888d5ac186a1f51aec84594eaa09acdfeb68)\nPackage name @openzeppelin-4/contracts impersonates the @openzeppelin/contracts scope but ships no Solidity contracts — only index.js, executed via lifecycle scripts. index.js enumerates process.env for credential-shaped keys (KEY, TOKEN, SECRET, AWS, GITHUB, NPM, MNEMONIC, WALLET, INFURA, etc.), reads installer secret files including ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.kube/config, ~/.docker/config.json, ~/.netrc, ~/.npmrc, ~/.gitconfig, ~/.git-credentials, gcloud application default credentials, Solana/Anchor/Sui keys, Foundry keystores, and project.env files, then POSTs the collected data to https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09. Delivery uses spawn(process.execPath, ['-e', src], { detached: true, stdio: 'ignore' }) with a randomized 60–240 second delay, and the script bails out when the hostname or username matches sandbox/scanner patterns (scan-, detonation, sandbox, ubuntu-fc-uvm) or when canary env markers are present, evading install-time analysis.\n","modified":"2026-08-12T09:45:11.708584701Z","published":"2026-08-11T15:16:48Z","database_specific":{"iocs":{"urls":["https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09"]},"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-017361","import_time":"2026-08-11T15:26:48.469062997Z","modified_time":"2026-08-11T15:16:48Z","sha256":"2841eb854dad391b8cf3d290704a888d5ac186a1f51aec84594eaa09acdfeb68"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-017364","import_time":"2026-08-11T15:26:48.833021928Z","modified_time":"2026-08-11T15:17:15Z","sha256":"af69458eaa45c49ecd88e7c778bb02f44871683f400ae81b9e5640e8c1710842"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openzeppelin-4/contracts/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openzeppelin-4/contracts/v/1.0.0"}],"affected":[{"package":{"name":"@openzeppelin-4/contracts","ecosystem":"npm","purl":"pkg:npm/%40openzeppelin-4/contracts"},"versions":["1.0.1","1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"0d49caf08b7ed3f15b70426b187a7647c403e4d8","sha512_sri":"sha512-xdFmvYYbmuGfHKfOq/nSSHuYT5vjUv5pNFESA2qvIam+k0e1zJbnw1+NR35TZvcA6vMlhK4MLhK464uj09Cf8A=="},"filename":"contracts-1.0.1.tgz"}],"evidence_files":[{"path":"index.js","sha256":"b7d297845b21b9e50cb6b4229f60adbd7af572f1c8038b56db8213be1436fd13","tlsh":"9451b683a2fe55a9126393e5e6236235823bf240b016d4e4f3ac54415fdb164c9b35fc"},{"tlsh":"e8e026300d52a33321e00ad6257bc85da0a6aa1a51883c0553c361ce82edb7284ff60e","path":"package.json","sha256":"40792c0d6846ac1e32a7cc51bf22be727b2cc4b5c9afc16221226b26c4da2468"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@openzeppelin-4/contracts/MAL-2026-13737.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}