MAL-2026-13346Malicious code in hdkey-wallet (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | hdkey-wallet | 2.1.0 |
{"modified":"2026-08-05T15:39:52Z","published":"2026-08-05T15:39:52Z","schema_version":"1.7.4","id":"MAL-2026-13346","summary":"Malicious code in hdkey-wallet (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4b36c64fed7b6d50787a971cc649c1f97605f6ea7027f388e9185ea85a580013)\nOn module load, index.js reads the complete process.env object along with hostname, username, home directory, platform, and current working directory, JSON-encodes and base64-wraps the payload, and transmits it via https.get to api.telegram.org's Bot API using a hardcoded bot token and chat_id 8969499041. A tmpdir flag file guards against repeated exfiltration. The package name and README present it as a drop-in replacement for the legitimate `hdkey` library, and the module attempts to require('hdkey') and re-export it when present, using the real library as a functional cover for the credential theft that fires on require(). Environments commonly holding secrets such as AWS_*, NPM_TOKEN, and GITHUB_TOKEN in process.env are directly exposed to the attacker-controlled Telegram bot.\n","affected":[{"package":{"ecosystem":"npm","name":"hdkey-wallet"},"versions":["2.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"0f8b5505e3627b2d23d7e45acb9e66b7959ab5b083a44c022e7e8f4e7c55fa78","tlsh":"e02141cc27f1f98e123361d1656f750bb2bbcae24888ea60d1a4d5c32f741c89965398"}],"package_integrity":[{"filename":"hdkey-wallet-2.1.0.tgz","hashes":{"sha1":"5baaa0f0825d784028dcc6e42997ea19b7fede4f","sha512_sri":"sha512-U//ZHzPrjKkQ/Fpa5bVYgDjBva3ZQR1xz4dg7ZLKacYjgWDyq0WsLTAZSS0szorYvC0RqPgJ/QhJA/Na6z96tA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/hdkey-wallet/v/2.1.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015785","import_time":"2026-08-05T16:13:44.947783897Z","modified_time":"2026-08-05T15:39:52Z","sha256":"4b36c64fed7b6d50787a971cc649c1f97605f6ea7027f388e9185ea85a580013","source":"amazon-inspector","versions":["2.1.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0