Malicious code in @web3-helpers/core (npm)
MAL-2026-10611
Published · Modified
Description
__
Source: amazon-inspector (9d5230cf08adcdf1d9108129f5c80e569b74774b7f2cb5e55aeb60be8d737225)
At npm install time the preinstall script (dist/index.min.js) reads installer-owned secrets — ~/.ssh/id_rsa, ~/.env, ~/.env.local, ~/.wallet.json — and iterates process.env for keys matching PRIVATE_*, MNEMONIC*, and SECRET*. Extracted content is scanned for 64-hex and WIF private keys and posted, along with the installer's hostname and username, to https://api.telegram.org/bot<!(node -e "require('./dist/index.min.js')...")) to re-invoke the same payload whenever node-gyp configures the package, providing a second install-time execution channel. The package name mimics legitimate Web3 helper libraries, package.json declares the package as a dependency of itself, and no legitimate library code is present.
References
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.2
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.1
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.5
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.3
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.0
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.4
- PACKAGE https://www.npmjs.com/package/@web3-helpers/core/v/1.0.6
Ready to move
Start Securing
Free, no credit card | First findings in minutes