npm · Malicious package advisory
Malwarecb-wallet-http
GHSA-jhp6-8xc5-6544
Malicious code in cb-wallet-http (npm)
Details
**Severity:** Critical
**Affected versions:** `= 0.0.1`
## Source: amazon-inspector (e8d704c0a6a48da0e2fef8eddcd1f98e7d380c3e19f22753f3df51d9893f60ce)
Package name mimics Coinbase's internal `cb-wallet-*` namespace to capture dependency-confusion resolutions. On `npm install` (postinstall.js) and on `require('cb-wallet-http')` (index.js), the package issues an HTTPS GET to the hardcoded endpoint `https://icy-cell-fb53.gh0stfqce25.workers.dev/poc`, transmitting the package name and Node.js runtime version to a third-party Cloudflare Workers domain registered under a personal handle (`gh0stfqce25.workers.dev`) unrelated to Coinbase. The package's own description self-identifies as a 'RESERVED PLACEHOLDER — coordinated security-research namespace claim' with the repository `github.com/gh0stfqce/npm-namespace-claims`. Regardless of the author's stated research intent, any organization that installs this package via misconfigured registry resolution leaks host/build-topology identifiers to the operator of the worker without consent, fingerprinting which builds are vulnerable to dependency confusion against Coinbase's namespace.
---
Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/924e3cfb512a9097299503a28807f7cbe55b2975/osv/malicious/npm/cb-wallet-http/MAL-2026-4507.json))
**References:**
- https://github.com/ossf/malicious-packages/blob/924e3cfb512a9097299503a28807f7cbe55b2975/osv/malicious/npm/cb-wallet-http/MAL-2026-4507.json
- https://www.npmjs.com/package/cb-wallet-http/v/0.0.1
- https://github.com/advisories/GHSA-jhp6-8xc5-6544Compromised versions (1)
- = 0.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.