OpenSSF/OSV advisory MAL-2026-3666 confirms this npm version as malicious. the analysis found that this package has a garbage randomized name ('01-0redi7qgbz0uv'), empty description, placeholder test script, and an index.js that is not valid JavaScript confirms hyphenated/numeric-leading identifiers that cannot be parsed). It has no functional code whatsoever...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in 01-0redi7qgbz0uv (npm)
Details
the analysis found that this package has a garbage randomized name ('01-0redi7qgbz0uv'), empty description, placeholder test script, and an index.js that is not valid JavaScript confirms hyphenated/numeric-leading identifiers that cannot be parsed). It has no functional code whatsoever. Its sole observable effect is to pin 40+ obscure wallet/crypto/trading-themed dependencies at 'latest' (walletgeninjsio, transferbwallets, balancetracking, arbitexchange, cryptoperfume, -rypto-ompareinfo, etc.). This matches the meta-package dependency-delivery pattern: the package itself contains no payload, but installing it forces installation of an arbitrary batch of attacker-controlled packages at whatever the latest version happens to be. Under the generic-placeholder-metadata-plus-network calibration (placeholder metadata + indirect supply-chain reach), combined with (a) non-functional entrypoint, (b) randomized name indicating no intended human consumer, and (c) crypto-themed transitive targets at floating 'latest' ranges, there is no legitimate use case for this package.
Decision reason
OSV/OpenSSF confirms 01-0redi7qgbz0uv@1.0.0 as malicious package MAL-2026-3666. Malicious code in 01-0redi7qgbz0uv (npm)