VYPR

npm · Malicious package advisory

Malware

blockchain-helper-0

GHSA-c2vr-ppqh-jhf8

Malicious code in blockchain-helper-0 (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

**Note:** *This report is updated by a verification record*

Crypto/SSH/wallet stealer (self-labeled "CRYPTO STEALER"). postinstall scripts/postinstall.js auto-execs, src/index.js harvests ~/.ssh/id_rsa + wallet keys/seeds + env and exfils to hardcoded Telegram bot 8227918239:AAGEMDrBZluDsBBYPxfSyMuv2l3FY8cZCcs chat 6433587894. Auto-exec + hardcoded attacker Telegram exfil; "blockchain-helper" identity has no reason to read SSH/wallet keys.## Source: amazon-inspector (8b9fac34e13ad38cb702f7aad434d18aa276005fe5fa4cbe48c7eb65af26623d)
The package was found to contain malicious code or consuming dependency that contains malicious code

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/05f0193d4d422ecc1ff043a015eb39c430039823/osv/malicious/npm/blockchain-helper-0/MAL-2026-5352.json))

**References:**
- https://app.safedep.io/community/malysis/01KTN3QACESWZP4EK3W7D1JJGC
- https://github.com/ossf/malicious-packages/blob/05f0193d4d422ecc1ff043a015eb39c430039823/osv/malicious/npm/blockchain-helper-0/MAL-2026-5352.json
- https://www.npmjs.com/package/blockchain-helper-0/v/1.0.0
- https://github.com/advisories/GHSA-c2vr-ppqh-jhf8

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.