MAL-2026-15637

    Dashboard / Malicious Package / MAL-2026-15637

    MAL-2026-15637

    Published: 31 Aug 2026Last Modified: 31 Aug 2026

    Summary: Malicious code in test__123q1 (npm)

    Details: Source: amazon-inspector (ac33922c804a14a307d55fb3dc80531482503bee2c96cc7fa4a487101c70e7d6) The package declares a postinstall hook (`node dist/script.js`) while its declared main entry (`dist/index.js`) is an inert 105-byte stub, so the entire behavior fires at `npm install` time. The postinstall script walks the installer's home directory and common workspace folders (Desktop, Documents, Downloads, Projects, Backups) and (1) reads browser wallet extension profiles for MetaMask, Phantom, Trust, Coinbase, OKX, Rabby, Keplr, Solflare, TronLink, Ronin, and Exodus, along with desktop wallet stores for Exodus, Electrum, Bitcoin Core, Ledger Live, Trezor Suite, Wasabi, and Sparrow, plus any files matching seed/mnemonic/bip39/privatekey/keystore keywords; (2) enumerates a hardcoded list of sensitive files including `.env*`, `.npmrc`, `.yarnrc`, `.pnpmrc`, `.netrc`, `.git-credentials`, `.gitconfig`, `id_rsa`/`id_ed25519`/`id_ecdsa`, `.pem`/`private.key`, `aws.json`, `gcloud.json`, `service-account.json`, and `firebase-adminsdk.json`. Collected material is packaged with `tar` and uploaded to a hardcoded Telegram bot endpoint at `https://api.telegram.org/bot<BOT_TOKEN>/sendDocument`. The script additionally harvests the installer's npm auth token, writes `//registry.npmjs.org/:_authToken=${token}` into an `.npmrc`, queries `registry.npmjs.org/-/whoami` and `registry.npmjs.org/-/v1/search` to enumerate the victim maintainer's other packages, and copies its own `dist` payload into them via `fs.cp('dist', pathToInject, { recursive: true })` to republish malicious versions under the victim's identity.

    Affected packages

    Package

    Name: test__123q1

    Purl: pkg:npm/test__123q1

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    4.3.5