{"id":"MAL-2026-6694","summary":"Malicious code in thirdwebb (npm)","details":"Malicious npm package published as part of a coordinated DeFi-themed infostealer campaign. `thirdwebb` is a typosquat of the legitimate `thirdweb` package. It uses a side-loader technique, pulling in `log-taker` as a transitive dependency; the infostealer runs automatically via that dependency's `postinstall` hook. The payload harvests cryptocurrency wallet vaults (MetaMask, Phantom, Solflare, OKX, Coinbase, TrustWallet, Backpack, TronLink), browser cookies and credentials, SSH keys, AWS credentials, `.npmrc` tokens, Docker config, shell history, and password manager databases, exfiltrating all data to the C2 domain `log-taker.store`.","modified":"2026-06-30T21:01:39.364337206Z","published":"2026-06-30T00:00:00Z","database_specific":{"malicious-packages-origins":null},"references":[{"type":"REPORT","url":"https://safedep.io/defi-infostealer-fake-arbitrage-bot-npm/"}],"affected":[{"package":{"name":"thirdwebb","ecosystem":"npm","purl":"pkg:npm/thirdwebb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/thirdwebb/MAL-2026-6694.json","iocs":{"domains":["log-taker.store"]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","cweId":"CWE-506","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}