OpenSSF/OSV advisory MAL-2026-17179 confirms this npm version as malicious. The package's postinstall hook runs `node./loader.js`, which base64-decodes an ~8 KB embedded blob, XOR-decrypts it with a hardcoded 32-byte key, and pipes the resulting bytes into a detached, window-hidden `python -c -` child process via stdin. The loader also silently `pip install`s `requests` if missing. The advertised library surface in `index.js` is an explicit stub whose `connect()` throws, and `package.json`...
This report applies to wallet-connect-adapter@1.4.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.