MAL-2026-3666

    Dashboard / Malicious Package / MAL-2026-3666

    MAL-2026-3666

    Published: 12 May 2026Last Modified: 13 May 2026

    Summary: Malicious code in 01-0redi7qgbz0uv (npm)

    Details: Source: amazon-inspector (5ceb633970757ab5d5ee0b64512c18d46be8402ac2169769101655a697ee5d6d) the analysis found that this package has a garbage randomized name ('01-0redi7qgbz0uv'), empty description, placeholder test script, and an index.js that is not valid JavaScript confirms hyphenated/numeric-leading identifiers that cannot be parsed). It has no functional code whatsoever. Its sole observable effect is to pin 40+ obscure wallet/crypto/trading-themed dependencies at 'latest' (walletgeninjsio, transferbwallets, balancetracking, arbitexchange, cryptoperfume, -rypto-ompareinfo, etc.). This matches the meta-package dependency-delivery pattern: the package itself contains no payload, but installing it forces installation of an arbitrary batch of attacker-controlled packages at whatever the latest version happens to be. Under the generic-placeholder-metadata-plus-network calibration (placeholder metadata + indirect supply-chain reach), combined with (a) non-functional entrypoint, (b) randomized name indicating no intended human consumer, and (c) crypto-themed transitive targets at floating 'latest' ranges, there is no legitimate use case for this package.

    Affected packages

    Package

    Name: 01-0redi7qgbz0uv

    Purl: pkg:npm/01-0redi7qgbz0uv

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0