VYPR

npm · Malicious package advisory

Malware

fuels-typegen

MAL-2026-15593

Malicious code in fuels-typegen (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (f4dcadcdf880021763232df96239a6a07acd6360bfcd941ae8026a37aee2eb2f)
The package name resembles the legitimate @fuel-ts/typegen. On execution of the CLI in bin/cli.js, the code collects the local username (whoami / os.userInfo), os.hostname(), platform, and package name and POSTs them as JSON to the hardcoded endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The manifest's own description states the package's purpose is to POST identifiers to an out-of-band callback, and the bin name (hyperliquid-composer) is unrelated to the package name, consistent with dependency-confusion or typosquat delivery.

## Source: ossf-package-analysis (d3a77505eb8f38e58c0a2b2a3b9ab7a0c4976077df0cef66e39b146eed5343ee)
The OpenSSF Package Analysis project identified 'fuels-typegen' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.