{"id":"MAL-2026-15984","summary":"Malicious code in gas-price-checker (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7f8f9689168acafb514d0ab0bb8710f1fce42e95560a2a0c7e0e6788e913e729)\nPackage advertises itself as a public-RPC gas price checker but on first call to the exported getGasPrice() API in src/envcheck.cjs it walks the caller's project directory scanning.env/.json/.js/.ts/keystore files with regexes for EVM private keys (0x[64 hex]), BIP-39 mnemonics, and strings matching private_key/mnemonic/api_key/secret/seed patterns. Matches (up to 40) are combined with a host fingerprint (sha256 of hostname|username), node version, and platform, encrypted with AES-256-GCM using a hardcoded base64 key (KEY_B64='Kkb8JVtVelmQmot/kC3JyY3WbjKH+LPln11DJ+bbTM0='), and POSTed to https://pkg-delivery-collector.vernal-dabs-tools.workers.dev/ingest. The scan and upload are gated by a one-shot _checked flag and run unconditionally the first time the advertised API is invoked. The exfiltration destination is undocumented, unrelated to the package's stated purpose (which requires no credentials), and the payload is encrypted with a shipped key to evade network inspection.\n\n## Source: ghsa-malware (459859928579f02596c8be07aa74f3388231d9fc9e94682740bde811d2ac3439)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-fw8f-xwq4-q3v8"],"modified":"2026-09-08T19:30:04.662432188Z","published":"2026-09-05T19:26:13Z","database_specific":{"malicious-packages-origins":[{"ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"459859928579f02596c8be07aa74f3388231d9fc9e94682740bde811d2ac3439","source":"ghsa-malware","id":"GHSA-fw8f-xwq4-q3v8","import_time":"2026-09-07T01:51:49.852995Z","modified_time":"2026-09-05T19:26:13Z"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019690","import_time":"2026-09-08T19:15:04.423676379Z","modified_time":"2026-09-08T19:09:50Z","sha256":"7f8f9689168acafb514d0ab0bb8710f1fce42e95560a2a0c7e0e6788e913e729"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fw8f-xwq4-q3v8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/gas-price-checker/v/1.0.0"}],"affected":[{"package":{"name":"gas-price-checker","ecosystem":"npm","purl":"pkg:npm/gas-price-checker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"cd7196e835fba13547d710f572539096b3ba80533a42e9e4bb6c42142f8583c82b7ec9","path":"src/envcheck.cjs","sha256":"d3f2dbe189c1138811ac2a2b4c5f4cd1e9334776fea314be95d277e98e0a6696"},{"path":"src/index.js","sha256":"a03093b85f3f985fa7e6c0cfc29dfda3b212afb1d770267d4e575efed8cb3b4c","tlsh":"cf2152f705b715a0836a36c2754f000ab32741867b4dacd5b7ee46109f5a6bac2526dc"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gas-price-checker/MAL-2026-15984.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}