MAL-2026-15638
Dashboard / Malicious Package / MAL-2026-15638
MAL-2026-15638
Summary: Malicious code in test__123q2 (npm)
Details: Source: amazon-inspector (1b08920ddaa70b578792ec7097f9d47047bdfe436a44475ed8274037ce6d6386) On npm install, the package's postinstall script sweeps the installer's home directory for crypto wallet and credential material and uploads it to an attacker-controlled Telegram bot. Targets include browser wallet extension profiles for MetaMask (nkbihfbeogaeaoehlefnkodbefgpgknn), Phantom, Trust, Coinbase, OKX, Rabby, Keplr, TronLink, Ronin, Solflare and Exodus; desktop wallets Exodus, Atomic, Electrum, Bitcoin Core (wallet.dat), Ledger Live, Trezor Suite, Wasabi, Sparrow, Guarda, Coinomi and Jaxx; and files under Desktop, Documents, Downloads and Projects matching mnemonic/seed/bip39/privatekey keywords plus.env,.npmrc,.netrc, id_rsa and ~/.aws material. Collected files are tarballed via the `tar` dependency and POSTed as a document to a hardcoded Telegram Bot API endpoint (https://api.telegram.org/bot<BOT_TOKEN>/sendDocument); the destination is not user-configurable. The package name and version carry no legitimate functionality that would justify this behavior.
Affected packages
Package
Name: test__123q2
Purl: pkg:npm/test__123q2
Affected ranges
Type: N/A
Events:
