VYPR

npm · Malicious package advisory

Malware

oleh-modal

MAL-2026-17516

Malicious code in oleh-modal (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cf2aebc282014a7dfa6ef1726083d23bcc9cc3eca76c814d4e775b7b10021545)
Package [email protected] is a credential-harvesting phishing kit disguised as a wallet-connect modal component. It renders fake MetaMask/Phantom/Rabby/OKX 'restore vault' modals that link to the legitimate extensions' restore-vault URLs to reinforce the deception, then captures the user's typed seed phrase / password characters via sendKeyToBackendAPI and POSTs them to a hardcoded backend at https://api.wagmiwallet.org/api/keys along with wallet_type, user_id, and enriched geolocation metadata (IP via api.ipify.org, city/region/country via ipapi.co). A persistent WebSocket connection to wss://api.wagmiwallet.org subscribes to a 'showMacModal' event that lets a remote operator trigger a spoofed macOS admin-authentication prompt on demand in the host application; captured mac_user_name and keystrokes from that dialog are forwarded through the same exfiltration path. Configuration references serverUrl 'https://wagmirequest.la' and backendUrl 'https://api.wagmiwallet.org', typosquats of wagmi.sh. Any consumer application that renders this component will forward its end users' wallet mnemonics and OS credentials to the attacker endpoint.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.