{"id":"MAL-2026-5861","summary":"Malicious code in solana-mev-bot (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e65516d3e042858742ebfee878ff2de6361994ce0155dcbf53c8e0f24cd5fafb)\nbot.js performs a hardcoded HTTPS GET to api.telegram.org's bot sendMessage endpoint, transmitting host fingerprint data collected via os.hostname(), os.userInfo(), and process.platform. The file also imports child_process and reads from the filesystem (fs.existsSync / fs.readFileSync) alongside the network exfiltration primitive. The destination is an attacker-operated Telegram bot, used as an exfiltration channel to siphon installer host identity and likely credential/wallet material from disk. The package name impersonates a Solana MEV trading utility to lure crypto users into running it.\n","aliases":["GHSA-8gg8-q73f-wv82"],"modified":"2026-09-01T11:31:02.322893247Z","published":"2026-06-16T03:00:10Z","database_specific":{"malicious-packages-origins":[{"sha256":"e65516d3e042858742ebfee878ff2de6361994ce0155dcbf53c8e0f24cd5fafb","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-006744","import_time":"2026-06-16T03:49:20.111243144Z","modified_time":"2026-06-16T03:00:10Z"},{"versions":["1.0.0"],"id":"RLMA-2026-05617","import_time":"2026-07-20T13:14:51.358550599Z","modified_time":"2026-07-20T10:59:10Z","sha256":"104cf256dd975fabf081224cccbc73607bbd9abef148c94be613c45f61b6358a","source":"reversing-labs"},{"source":"reversing-labs","id":"RLUA-2026-06498","import_time":"2026-09-01T11:18:24.769343043Z","modified_time":"2026-08-24T17:11:28Z","sha256":"d3fc6e7ed52661b77a28cded01132cdb0f840ba8c5fb27255628e30492e2aa75"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/solana-mev-bot/v/1.0.0"},{"type":"WEB","url":"https://research.jfrog.com/post/solana-fakefix"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8gg8-q73f-wv82"}],"affected":[{"package":{"name":"solana-mev-bot","ecosystem":"npm","purl":"pkg:npm/solana-mev-bot"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bot.js","sha256":"a3ebeaf11b3c1efde4a7956c0c8bd47a29726c15e825d5a46f2bde2ded3875e9","tlsh":"bea184506efb623430f76cea9fb71c02251be603f900d994758d87d24fba128de129ad"}],"package_integrity":[{"filename":"solana-mev-bot-1.0.0.tgz","hashes":{"sha512_sri":"sha512-jjVZDLDfs2dxwoejSK45GIfoMAC6yWCnythKJdPdtMBDhe2AlRhCK1YaBi396AjL5eI6YIJvMfE8rBqHWtbTgQ==","sha1":"2ec4f70010359d3e333fb7e05c6fbf2020a59c0e"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/solana-mev-bot/MAL-2026-5861.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}