OpenSSF/OSV advisory MAL-2026-11532 confirms this npm version as malicious. The postinstall.js script, which runs automatically on `npm install`, harvests a broad set of installer-owned secrets and identity data and exfiltrates them to two hardcoded attacker-controlled destinations. Collected data includes sensitive environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, HELIUS/INFURA/ALCHEMY keys, MNEMONIC, SEED_PHRASE, SOLANA_PRIVATE_KEY, and similar), the contents of...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @zzzgenesis00/solana-wallet-adapter (npm)
Details
The postinstall.js script, which runs automatically on `npm install`, harvests a broad set of installer-owned secrets and identity data and exfiltrates them to two hardcoded attacker-controlled destinations. Collected data includes sensitive environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_*, HELIUS/INFURA/ALCHEMY keys, MNEMONIC, SEED_PHRASE, SOLANA_PRIVATE_KEY, and similar), the contents of ~/.ssh, ~/.npmrc, and ~/.gitconfig, Chrome/Firefox profile artifacts (Cookies, Login Data, key4.db), the output of `npm whoami` and `git config`, and listings of common wallet directories (.bitcoin,.ethereum,.solana,.metamask,.exodus,.electrum). About 1.5-3.5 seconds after postinstall start, the harvested JSON is sent via HTTPS GET to `api.telegram.org` using a hardcoded bot token and chat_id (bot/chat 7231970337) and via HTTPS POST to `40f955f39128bd79-178-249-214-24.serveousercontent.com/collect` (a Serveo tunnel). The package impersonates the anza-xyz Solana publisher via a false `author` field and a non-existent repository link, wraps the harvester in mangled identifiers (_stq/_dgx/_uiz/_cp/_ht/_tk/_ch/_co/_ex) with a cover-story comment 'postinstall environment verification', and re-exports `./index.js` to appear functional. The stated wallet-adapter purpose does not justify any of the observed reads.
Decision reason
OpenSSF Malicious Packages via OSV confirms @zzzgenesis00/solana-wallet-adapter@0.18.0 as malicious (MAL-2026-11532): Malicious code in @zzzgenesis00/solana-wallet-adapter (npm)