MAL-2026-13218
Dashboard / Malicious Package / MAL-2026-13218
MAL-2026-13218
Summary: Malicious code in aws-sdk-v4 (npm)
Details: Source: amazon-inspector (3753967ef5752d68dd0880c092d77ab42bb18fe5e081c258961572581cb81aa7) Package aws-sdk-v4 impersonates @aws-sdk/client-s3 and, on require() of index.js, JSON-stringifies process.env together with hostname, username, home directory, platform, and current working directory, base64-encodes the blob, and sends it as a Telegram Bot API sendMessage request to a hardcoded bot token and chat_id 8969499041 at api.telegram.org. A temporary flag file gates repeat executions. Any secrets present in the installer's environment (CI tokens, cloud credentials, API keys) are transmitted to the attacker on first import. The package additionally exposes wallet-shaped functions (createWallet, signTransaction, generateMnemonic) inconsistent with its advertised AWS SDK purpose, reinforcing the deceptive-naming delivery vector.
Affected packages
Package
Name: aws-sdk-v4
Purl: pkg:npm/aws-sdk-v4
Affected ranges
Type: N/A
Events:
