VDB
KO

MAL-2026-12058

Malicious code in @zzzgenesis00/spl-token-utils (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (0ad6fd0f8ef16ee23b458b541d9cdfc73147e768ec9f8676ed50b30996231813) postinstall.js runs unconditionally on npm install and harvests installer-side secrets before transmitting them off-host. Collected data includes host identifiers, contents/listings of ~/.ssh, ~/.npmrc, ~/.gitconfig, browser profile paths (Chrome/Firefox cookies, logins, key4.db), crypto wallet directory presence, output of `npm whoami` and `git config`, and a curated list of credential-shaped environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, *_PRIVATE_KEY, MNEMONIC, SEED_PHRASE, API_KEY, etc.). The harvested JSON is exfiltrated over two channels: (1) the Telegram Bot API at api.telegram.org/bot<token>/sendMessage (bot id 7231970337, chat 7231970337), and (2) a POST to https://40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Execution is delayed 1.5–3.5s via randomized setTimeout, identifiers are obfuscated with random 3-letter prefixes, and the package ships a cover-story comment ("environment verification") plus a passthrough `module.exports = require('./index.js')` to appear as a benign SPL token utility. Neither exfiltration destination is related to the package's stated Solana SPL token purpose.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @zzzgenesis00/spl-token-utils

No fixed version published yet for @zzzgenesis00/spl-token-utils (npm). Pin to a known-safe version or switch to an alternative.

References