npm · Malicious package advisory
Malware@wethenorth12/solana-wallet-adapter
MAL-2026-12101
Malicious code in @wethenorth12/solana-wallet-adapter (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (14e7d05f22a60d86ce4aea030108a6f50a69b85ce9bb0219eb59fbe2dbc3bbb2) On require(), index.js JSON-encodes the full process.env plus hostname, username, homedir, platform, cwd, and package metadata, base64-encodes the payload, and sends it as a Telegram Bot API sendMessage GET request to a hardcoded bot token and chat_id (8969499041). A marker file in the OS tmpdir gates the beacon to fire once per host. The package impersonates @solana/wallet-adapter-base: the author field is spoofed as 'anza-xyz', the README advertises a 'drop-in replacement', and the module attempts to require the real @solana/wallet-adapter-base and re-export it so consumers see a working facade while the exfiltration runs silently. Developer and CI environments routinely carry AWS_*, GITHUB_TOKEN, NPM_TOKEN, and other credential-shaped variables, so a full env dump to an attacker endpoint is credential theft against the installer.
Compromised versions (1)
- 0.18.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.