OpenSSF/OSV advisory MAL-2026-11529 confirms this npm version as malicious. postinstall.js runs automatically on `npm install` and enumerates installer-owned secret material: SSH private keys under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile cookie/login/key databases, cryptocurrency wallet directories (metamask, exodus, electrum, etc.), and a curated list of sensitive environment variables including NPM_TOKEN, AWS keys, GitHub tokens, ETHEREUM_PRIVATE_KEY, and MNEMONIC...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @zzzgenesis00/crypto-config (npm)
Details
postinstall.js runs automatically on `npm install` and enumerates installer-owned secret material: SSH private keys under ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile cookie/login/key databases, cryptocurrency wallet directories (metamask, exodus, electrum, etc.), and a curated list of sensitive environment variables including NPM_TOKEN, AWS keys, GitHub tokens, ETHEREUM_PRIVATE_KEY, and MNEMONIC. It also invokes `npm whoami` and `git config user.email` to bind the exfil to a specific identity. The collected profile is sent via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and via HTTPS POST to a hardcoded serveousercontent.com tunnel endpoint at /collect; neither destination is caller-configurable. Delivery is jittered via setTimeout(1500 + Math.random()*2000) and identifiers throughout the script are mangled (_vaa, _zmj, _rlb, _cp, _ht, _tk, _ch, _co, _ex). The package name, author field (`lorenwest`, the maintainer of the legitimate `config` package), and homepage impersonate a benign configuration library, and index.js transparently proxies to the real `config` package when present as a cover for the install-time payload.
Decision reason
OpenSSF Malicious Packages via OSV confirms @zzzgenesis00/crypto-config@2.0.1 as malicious (MAL-2026-11529): Malicious code in @zzzgenesis00/crypto-config (npm)