{"id":"MAL-2026-4708","summary":"Malicious code in wallet-agent-ai (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3bb49d047eeab68307095cf3a30ff0d42d745855890f181e4cb53dc2f6903e91)\ndist/agent.js contains a hardcoded Telegram Bot API endpoint (https://api.telegram.org) used in a fetch/POST call near references to process.env. The package presents itself as a wallet/AI agent but ships a bot-token-bearing C2 channel inside its compiled JS, alongside a third-party API call to api.astrolescent.com. This is the canonical credential/data exfiltration pattern: caller-supplied or environment-derived data is POSTed to a Telegram bot controlled by the package author, giving the author silent access to whatever inputs or env values reach this code path. There is no legitimate reason for a wallet-related library to relay data through a hardcoded Telegram bot endpoint.\n","modified":"2026-05-27T00:32:09.943404866Z","published":"2026-05-24T07:26:29Z","withdrawn":"2026-05-26T19:01:24Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-004470","import_time":"2026-05-26T05:52:39.780881107Z","modified_time":"2026-05-24T07:26:34Z","sha256":"3bb49d047eeab68307095cf3a30ff0d42d745855890f181e4cb53dc2f6903e91","source":"amazon-inspector","versions":["1.0.1"]},{"sha256":"52ebcc1d038054657e9ec04e998713056e1b010188a95b18632b0786b08ee93a","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-004469","import_time":"2026-05-26T05:52:39.644061694Z","modified_time":"2026-05-24T07:26:29Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wallet-agent-ai/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wallet-agent-ai/v/1.0.2"}],"affected":[{"package":{"name":"wallet-agent-ai","ecosystem":"npm","purl":"pkg:npm/wallet-agent-ai"},"versions":["1.0.1","1.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/wallet-agent-ai/MAL-2026-4708.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"wallet-agent-ai-1.0.1.tgz","hashes":{"sha1":"61c27b09c64c457a35f55f8a8a191e4434179e23","sha512_sri":"sha512-lqvbpwkgWcOW9CdT3I6uwrzn/f6/CQAC5SELlGzOXveQ8vAoI1yona63qM0c7BBfEg7v6Rr/UeB/SRhG7jDr2A=="}}],"evidence_files":[{"path":"dist/agent.js","sha256":"eb69aab5eb9be86ff5c6bc8eec20eb220f532a5dffbd2dd409856c035815a78e","tlsh":"adf161365af5786038a3d18ca73b4007b4b9ba13740ce464b78cf1a56fdc12945f2abd"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}