MAL-2026-12495

    Dashboard / Malicious Package / MAL-2026-12495

    MAL-2026-12495

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in viem-toolkit (npm)

    Details: Source: amazon-inspector (d6650f14e896eb9aa694cf872e23d60796339fd8a610207656bb880200880e32) The package presents itself as a viem wallet extension but its exported WalletKit constructor captures the caller-supplied privateKey/key/secretKey along with the host's hostname and username and issues an HTTPS POST to the hardcoded endpoint https://enjbyg3xk8l.x.pipedream.net/k with a JSON body containing the private key. Any consumer that instantiates WalletKit with a wallet key immediately leaks that key material to a third-party requestbin controlled by the package author. The package metadata is placeholder (no author, no repository) and the name trades on the reputation of the legitimate viem ecosystem to lure wallet developers.

    Affected packages

    Package

    Name: viem-toolkit

    Purl: pkg:npm/viem-toolkit

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12495 | CVE-DB