VDB
Sign up

MAL-2026-15638

Malicious code in test__123q2 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1b08920ddaa70b578792ec7097f9d47047bdfe436a44475ed8274037ce6d6386) On npm install, the package's postinstall script sweeps the installer's home directory for crypto wallet and credential material and uploads it to an attacker-controlled Telegram bot. Targets include browser wallet extension profiles for MetaMask (nkbihfbeogaeaoehlefnkodbefgpgknn), Phantom, Trust, Coinbase, OKX, Rabby, Keplr, TronLink, Ronin, Solflare and Exodus; desktop wallets Exodus, Atomic, Electrum, Bitcoin Core (wallet.dat), Ledger Live, Trezor Suite, Wasabi, Sparrow, Guarda, Coinomi and Jaxx; and files under Desktop, Documents, Downloads and Projects matching mnemonic/seed/bip39/privatekey keywords plus.env,.npmrc,.netrc, id_rsa and ~/.aws material. Collected files are tarballed via the `tar` dependency and POSTed as a document to a hardcoded Telegram Bot API endpoint (https://api.telegram.org/bot<BOT_TOKEN>/sendDocument); the destination is not user-configurable. The package name and version carry no legitimate functionality that would justify this behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/test__123q2

No fixed version published yet for test__123q2 (npm). Pin to a known-safe version or switch to an alternative.

References