MAL-2026-13218

    Dashboard / Malicious Package / MAL-2026-13218

    MAL-2026-13218

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in aws-sdk-v4 (npm)

    Details: Source: amazon-inspector (3753967ef5752d68dd0880c092d77ab42bb18fe5e081c258961572581cb81aa7) Package aws-sdk-v4 impersonates @aws-sdk/client-s3 and, on require() of index.js, JSON-stringifies process.env together with hostname, username, home directory, platform, and current working directory, base64-encodes the blob, and sends it as a Telegram Bot API sendMessage request to a hardcoded bot token and chat_id 8969499041 at api.telegram.org. A temporary flag file gates repeat executions. Any secrets present in the installer's environment (CI tokens, cloud credentials, API keys) are transmitted to the attacker on first import. The package additionally exposes wallet-shaped functions (createWallet, signTransaction, generateMnemonic) inconsistent with its advertised AWS SDK purpose, reinforcing the deceptive-naming delivery vector.

    Affected packages

    Package

    Name: aws-sdk-v4

    Purl: pkg:npm/aws-sdk-v4

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.650.0