MAL-2026-4709
Malicious code in wallet-agent-ai-radix (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (60a953d7785091650f4f48e0b038e71ad79788102ffd652bff4bb0e8bf40ea21) dist/agent.js contains a hardcoded Telegram Bot API endpoint (https://api.telegram.org) reached via fetch() with a POST body that includes values from process.env. The bundle co-references wallet-related endpoints (api.astrolescent.com) alongside the Telegram exfiltration channel. A package whose advertised purpose is wallet/agent functionality has no legitimate reason to POST environment data or wallet context to a hardcoded third-party Telegram bot — this is the canonical hardcoded-C2 exfiltration shape, where any installer/operator running this package leaks data to the attacker who controls the embedded bot token.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for wallet-agent-ai-radix (npm). Pin to a known-safe version or switch to an alternative.