MAL-2026-11532
Dashboard / Malicious Package / MAL-2026-11532
MAL-2026-11532
Summary: Malicious code in @zzzgenesis00/solana-wallet-adapter (npm)
Details: Source: amazon-inspector (313cd424f27cb12cf28c0ad6737c2b2d5b08ff37d8971ae65a3a0184a73d2c46) The postinstall.js script, which runs automatically on `npm install`, harvests a broad set of installer-owned secrets and identity data and exfiltrates them to two hardcoded attacker-controlled destinations. Collected data includes sensitive environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, HELIUS/INFURA/ALCHEMY keys, MNEMONIC, SEED_PHRASE, SOLANA_PRIVATE_KEY, and similar), the contents of ~/.ssh, ~/.npmrc, and ~/.gitconfig, Chrome/Firefox profile artifacts (Cookies, Login Data, key4.db), the output of `npm whoami` and `git config`, and listings of common wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum). About 1.5-3.5 seconds after postinstall start, the harvested JSON is sent via HTTPS GET to `api.telegram.org` using a hardcoded bot token and chat_id (bot/chat 7231970337) and via HTTPS POST to `40f955f39128bd79-178-249-214-24.serveousercontent.com/collect` (a Serveo tunnel). The package impersonates the anza-xyz Solana publisher via a false `author` field and a non-existent repository link, wraps the harvester in mangled identifiers (_stq/_dgx/_uiz/_cp/_ht/_tk/_ch/_co/_ex) with a cover-story comment 'postinstall environment verification', and re-exports `./index.js` to appear functional. The stated wallet-adapter purpose does not justify any of the observed reads.
Affected packages
Package
Name: @zzzgenesis00/solana-wallet-adapter
Purl: pkg:npm/%40zzzgenesis00/solana-wallet-adapter
Affected ranges
Type: N/A
Events:
