OpenSSF/OSV advisory MAL-2026-17516 confirms this npm version as malicious. Package oleh-modal@1.0.0 is a credential-harvesting phishing kit disguised as a wallet-connect modal component. It renders fake MetaMask/Phantom/Rabby/OKX 'restore vault' modals that link to the legitimate extensions' restore-vault URLs to reinforce the deception, then captures the user's typed seed phrase / password characters via sendKeyToBackendAPI and POSTs them to a hardcoded backend at...
Package ships high-entropy non-source blobs.
dist/wallets/metamask/assets/fox_appear.rivView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/wallets/bitget/styles.cssView on unpkgThis report applies to oleh-modal@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package ships high-entropy non-source blobs.
dist/wallets/metamask/assets/fox_appear.rivView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/wallets/bitget/styles.cssView on unpkg