MAL-2026-11529

    Dashboard / Malicious Package / MAL-2026-11529

    MAL-2026-11529

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in @zzzgenesis00/crypto-config (npm)

    Details: Source: amazon-inspector (0059f996b08ee001bad27a2ec933573651b171f5b4fcde2b1e12b7a4388c7ca3) postinstall.js runs automatically on `npm install` and enumerates installer-owned secret material: SSH private keys under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile cookie/login/key databases, cryptocurrency wallet directories (metamask, exodus, electrum, etc.), and a curated list of sensitive environment variables including NPM_TOKEN, AWS keys, GitHub tokens, ETHEREUM_PRIVATE_KEY, and MNEMONIC. It also invokes `npm whoami` and `git config user.email` to bind the exfil to a specific identity. The collected profile is sent via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and via HTTPS POST to a hardcoded serveousercontent.com tunnel endpoint at /collect; neither destination is caller-configurable. Delivery is jittered via setTimeout(1500 + Math.random()*2000) and identifiers throughout the script are mangled (_vaa, _zmj, _rlb, _cp, _ht, _tk, _ch, _co, _ex). The package name, author field (`lorenwest`, the maintainer of the legitimate `config` package), and homepage impersonate a benign configuration library, and index.js transparently proxies to the real `config` package when present as a cover for the install-time payload.

    Affected packages

    Package

    Name: @zzzgenesis00/crypto-config

    Purl: pkg:npm/%40zzzgenesis00/crypto-config

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.1