test__123q2 @2.1.1
Vulnerability report · Last retrieved from osv.dev August 31, 2026 at 11:43 PM UTC
OSV ID
MAL-2026-15638
Ecosystem
npm
Summary
On npm install, the package's postinstall script sweeps the installer's home directory for crypto wallet and credential material and uploads it to an attacker-controlled Telegram bot. Targets include browser wallet extension profiles for MetaMask (nkbihfbeogaeaoehlefnkodbefgpgknn), Phantom, Trust, Coinbase, OKX, Rabby, Keplr, TronLink, Ronin, Solflare and Exodus; desktop wallets Exodus, Atomic, Electrum, Bitcoin Core (wallet.dat), Ledger Live, Trezor Suite, Wasabi, Sparrow, Guarda, Coinomi and Jaxx; and files under Desktop, Documents, Downloads and Projects matching mnemonic/seed/bip39/privatekey keywords plus.env,.npmrc,.netrc, id_rsa and ~/.aws material. Collected files are tarballed via the tar dependency and POSTed as a document to a hardcoded Telegram Bot API endpoint (https://api.telegram.org/bot<BOT_TOKEN>/sendDocument); the destination is not user-configurable. The package name and version carry no legitimate functionality that would justify this behavior.
Source: amazon-inspector (1b08920ddaa70b578792ec7097f9d47047bdfe436a44475ed8274037ce6d6386)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.