MAL-2026-12121
Dashboard / Malicious Package / MAL-2026-12121
MAL-2026-12121
Summary: Malicious code in @zzzgenesis00/hd-key-generator (npm)
Details: Source: amazon-inspector (6d1bce1ae0778169c4e5fb37721dfcc052c984efc60a257166adb4d20e2d39e5) @zzzgenesis00/hd-key-generator ships a postinstall.js that runs automatically on npm install. It enumerates ~/.ssh, ~/.npmrc, ~/.gitconfig, browser profile artifacts (Chrome/Firefox cookies, Login Data, key4.db), and cryptocurrency wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum), and scrapes environment variables shaped as credentials (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, *_PRIVATE_KEY, MNEMONIC, SEED_PHRASE, API keys). The collected data is transmitted via two hardcoded channels: an HTTPS GET to api.telegram.org bot sendMessage using an embedded bot token and chat_id, and an HTTPS POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com. The payload is self-labeled as 'postinstall environment verification', uses cryptic identifiers (_cgn, _qik, _gso, _cp, _ht, _tk, _ch, _co, _ex), and is triggered via setTimeout with random jitter to obscure execution. index.js is a thin wrapper that re-exports the legitimate 'hdkey' module when present, providing a typosquat-style cover for HD-wallet developers while the stealer runs.
Affected packages
Package
Name: @zzzgenesis00/hd-key-generator
Purl: pkg:npm/%40zzzgenesis00/hd-key-generator
Affected ranges
Type: N/A
Events:
