npm · Malicious package advisory
Malwareblockchain-helper-0
GHSA-c2vr-ppqh-jhf8
Malicious code in blockchain-helper-0 (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` **Note:** *This report is updated by a verification record* Crypto/SSH/wallet stealer (self-labeled "CRYPTO STEALER"). postinstall scripts/postinstall.js auto-execs, src/index.js harvests ~/.ssh/id_rsa + wallet keys/seeds + env and exfils to hardcoded Telegram bot 8227918239:AAGEMDrBZluDsBBYPxfSyMuv2l3FY8cZCcs chat 6433587894. Auto-exec + hardcoded attacker Telegram exfil; "blockchain-helper" identity has no reason to read SSH/wallet keys.## Source: amazon-inspector (8b9fac34e13ad38cb702f7aad434d18aa276005fe5fa4cbe48c7eb65af26623d) The package was found to contain malicious code or consuming dependency that contains malicious code --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/05f0193d4d422ecc1ff043a015eb39c430039823/osv/malicious/npm/blockchain-helper-0/MAL-2026-5352.json)) **References:** - https://app.safedep.io/community/malysis/01KTN3QACESWZP4EK3W7D1JJGC - https://github.com/ossf/malicious-packages/blob/05f0193d4d422ecc1ff043a015eb39c430039823/osv/malicious/npm/blockchain-helper-0/MAL-2026-5352.json - https://www.npmjs.com/package/blockchain-helper-0/v/1.0.0 - https://github.com/advisories/GHSA-c2vr-ppqh-jhf8
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.