Logo
npm

oleh-modal@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17516

Ecosystem

npm

Summary

Package oleh-modal@1.0.0 is a credential-harvesting phishing kit disguised as a wallet-connect modal component. It renders fake MetaMask/Phantom/Rabby/OKX 'restore vault' modals that link to the legitimate extensions' restore-vault URLs to reinforce the deception, then captures the user's typed seed phrase / password characters via sendKeyToBackendAPI and POSTs them to a hardcoded backend at https://api.wagmiwallet.org/api/keys along with wallet_type, user_id, and enriched geolocation metadata (IP via api.ipify.org, city/region/country via ipapi.co). A persistent WebSocket connection to wss://api.wagmiwallet.org subscribes to a 'showMacModal' event that lets a remote operator trigger a spoofed macOS admin-authentication prompt on demand in the host application; captured mac_user_name and keystrokes from that dialog are forwarded through the same exfiltration path. Configuration references serverUrl 'https://wagmirequest.la' and backendUrl 'https://api.wagmiwallet.org', typosquats of wagmi.sh. Any consumer application that renders this component will forward its end users' wallet mnemonics and OS credentials to the attacker endpoint.

Source: amazon-inspector (cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.