OpenSSF/OSV advisory MAL-2026-6693 confirms this npm version as malicious. Malicious npm package published as part of a coordinated DeFi-themed infostealer campaign. `thirdwb` is a typosquat of the legitimate `thirdweb` package. It uses a side-loader technique, pulling in `log-taker` as a transitive dependency; the infostealer runs automatically via that dependency's `postinstall` hook...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in thirdwb (npm)
Details
Malicious npm package published as part of a coordinated DeFi-themed infostealer campaign. `thirdwb` is a typosquat of the legitimate `thirdweb` package. It uses a side-loader technique, pulling in `log-taker` as a transitive dependency; the infostealer runs automatically via that dependency's `postinstall` hook. The payload harvests cryptocurrency wallet vaults (MetaMask, Phantom, Solflare, OKX, Coinbase, TrustWallet, Backpack, TronLink), browser cookies and credentials, SSH keys, AWS credentials, `.npmrc` tokens, Docker config, shell history, and password manager databases, exfiltrating all data to the C2 domain `log-taker.store`.
---
## Source: amazon-inspector (46722968fbda27cc58821cf8eb055f9c299d3984f794bc6c8554183a11f71304) The package was found to contain malicious code or consuming dependency that contains malicious code
Decision reason
OpenSSF Malicious Packages via OSV confirms thirdwb@0.0.8 as malicious (MAL-2026-6693): Malicious code in thirdwb (npm)