OpenSSF/OSV advisory MAL-2026-12124 confirms this npm version as malicious. This package impersonates the legitimate `tronweb` SDK (author field spoofed as 'tronprotocol') and runs a malicious postinstall.js at npm install time. The script enumerates ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile files (Cookies, Login Data, key4.db, logins.json), cryptocurrency wallet directories (metamask, exodus, electrum, ethereum, solana, tron), and a hardcoded list of credential-shaped...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @zzzgenesis00/tronweb3 (npm)
Details
This package impersonates the legitimate `tronweb` SDK (author field spoofed as 'tronprotocol') and runs a malicious postinstall.js at npm install time. The script enumerates ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome/Firefox profile files (Cookies, Login Data, key4.db, logins.json), cryptocurrency wallet directories (metamask, exodus, electrum, ethereum, solana, tron), and a hardcoded list of credential-shaped environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS keys, MNEMONIC, SEED_PHRASE, TRON_PRIVATE_KEY, etc.), packages them, and POSTs the payload to two hardcoded attacker endpoints: the Telegram Bot API (api.telegram.org/bot<token>/sendMessage) and a Serveo tunnel host at 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. Variable names are obfuscated (_rqp, _gzr, _zsw, _cp, _ht, _tk, _ch) and a comment frames the behavior as 'postinstall environment verification' as cover.
Decision reason
OpenSSF Malicious Packages via OSV confirms @zzzgenesis00/tronweb3@5.3.2 as malicious (MAL-2026-12124): Malicious code in @zzzgenesis00/tronweb3 (npm)