npm · Malicious package advisory
Malware01-0redi7qgbz0uv
MAL-2026-3666
Malicious code in 01-0redi7qgbz0uv (npm)
Details
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5ceb633970757ab5d5ee0b64512c18d46be8402ac2169769101655a697ee5d6d)
the analysis found that this package has a garbage randomized name ('01-0redi7qgbz0uv'), empty description, placeholder test script, and an index.js that is not valid JavaScript confirms hyphenated/numeric-leading identifiers that cannot be parsed). It has no functional code whatsoever. Its sole observable effect is to pin 40+ obscure wallet/crypto/trading-themed dependencies at 'latest' (walletgeninjsio, transferbwallets, balancetracking, arbitexchange, cryptoperfume, -rypto-ompareinfo, etc.). This matches the meta-package dependency-delivery pattern: the package itself contains no payload, but installing it forces installation of an arbitrary batch of attacker-controlled packages at whatever the latest version happens to be. Under the generic-placeholder-metadata-plus-network calibration (placeholder metadata + indirect supply-chain reach), combined with (a) non-functional entrypoint, (b) randomized name indicating no intended human consumer, and (c) crypto-themed transitive targets at floating 'latest' ranges, there is no legitimate use case for this package.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.