{"id":"MAL-2026-17516","summary":"Malicious code in oleh-modal (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545)\nPackage oleh-modal@1.0.0 is a credential-harvesting phishing kit disguised as a wallet-connect modal component. It renders fake MetaMask/Phantom/Rabby/OKX 'restore vault' modals that link to the legitimate extensions' restore-vault URLs to reinforce the deception, then captures the user's typed seed phrase / password characters via sendKeyToBackendAPI and POSTs them to a hardcoded backend at https://api.wagmiwallet.org/api/keys along with wallet_type, user_id, and enriched geolocation metadata (IP via api.ipify.org, city/region/country via ipapi.co). A persistent WebSocket connection to wss://api.wagmiwallet.org subscribes to a 'showMacModal' event that lets a remote operator trigger a spoofed macOS admin-authentication prompt on demand in the host application; captured mac_user_name and keystrokes from that dialog are forwarded through the same exfiltration path. Configuration references serverUrl 'https://wagmirequest.la' and backendUrl 'https://api.wagmiwallet.org', typosquats of wagmi.sh. Any consumer application that renders this component will forward its end users' wallet mnemonics and OS credentials to the attacker endpoint.\n","modified":"2026-10-04T23:45:20.817881482Z","published":"2026-10-04T23:27:14Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-04T23:40:46.543978657Z","modified_time":"2026-10-04T23:27:14Z","sha256":"cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020965"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/oleh-modal/v/1.0.0"}],"affected":[{"package":{"name":"oleh-modal","ecosystem":"npm","purl":"pkg:npm/oleh-modal"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"oleh-modal-1.0.0.tgz","hashes":{"sha1":"66e05aa225714eac39ea6bd3205000dc22729433","sha512_sri":"sha512-EUXUoDIY5L/ONz5Jcc07jt/41HEYV3YALtX/pNzmqzbo6vkxKJ/lxXVYPcuIAM7vXMpOa0Id3X5nCTlSJt4pQg=="}}],"evidence_files":[{"sha256":"e8bc1ad8e8628a784a23f739004c3a6d53160311e2311933ab751d5dc7f5f7e9","tlsh":"bec4fad4b3ad106e4123716aa93f11cdb33dd173561488a9be9c992c3fd481c43eabb9","path":"dist/index.cjs"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/oleh-modal/MAL-2026-17516.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}