npm

@zzzgenesis00/crypto-config @2.0.1

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC

Malicious

OSV ID

MAL-2026-11529

Ecosystem

npm

Summary

postinstall.js runs automatically on npm install and enumerates installer-owned secret material: SSH private keys under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile cookie/login/key databases, cryptocurrency wallet directories (metamask, exodus, electrum, etc.), and a curated list of sensitive environment variables including NPM_TOKEN, AWS keys, GitHub tokens, ETHEREUM_PRIVATE_KEY, and MNEMONIC. It also invokes npm whoami and git config user.email to bind the exfil to a specific identity. The collected profile is sent via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and via HTTPS POST to a hardcoded serveousercontent.com tunnel endpoint at /collect; neither destination is caller-configurable. Delivery is jittered via setTimeout(1500 + Math.random()*2000) and identifiers throughout the script are mangled (_vaa, _zmj, _rlb, _cp, _ht, _tk, _ch, _co, _ex). The package name, author field ( lorenwest , the maintainer of the legitimate config package), and homepage impersonate a benign configuration library, and index.js transparently proxies to the real config package when present as a cover for the install-time payload.

Source: amazon-inspector (0059f996b08ee001bad27a2ec933573651b171f5b4fcde2b1e12b7a4388c7ca3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.