Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in bip39-generator (npm)

0
High
Published: 08/05/2026 (08/05/2026, 15:39:31 UTC)
Source: GCVE Database
Product: bip39-generator

Description

The bip39-generator npm package version 3.1.2 is a malicious typosquatting package that exfiltrates environment variables and host information to an attacker's Telegram channel. It masquerades as a drop-in replacement for the legitimate bip39 package but exports non-functional wallet and mnemonic functions. On load, it collects sensitive environment data and sends it encoded via HTTPS GET requests to a hardcoded Telegram bot endpoint, potentially leaking API keys, cloud credentials, and CI secrets.

Affected software

npmghsa
bip39-generator
Affected versions
=3.1.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 23:00:56 UTC

Technical Analysis

The bip39-generator package (version 3.1.2) is a malicious npm package designed to steal sensitive information from the environment of any process that loads it. Upon loading, its index.js serializes the entire process environment variables along with host details such as hostname, username, home directory, platform, and current working directory. This data is base64-encoded and sent via an HTTPS GET request to a Telegram bot API endpoint using a hardcoded bot token and chat ID. The package exports stub functions that do not perform legitimate wallet or mnemonic operations, indicating it is a typosquatting lure targeting crypto developers. A temporary directory marker file prevents repeated data exfiltration attempts. This behavior results in leakage of potentially sensitive secrets and host identity to the attacker-controlled Telegram channel.

Potential Impact

Any process that installs and requires bip39-generator version 3.1.2 will leak its full environment variables and host identity information to an attacker-controlled Telegram channel. This can include API keys, cloud credentials, continuous integration secrets, and other sensitive data present in environment variables. The package does not perform legitimate cryptographic functions, so any dependent software relying on it will not function correctly, potentially causing operational issues in addition to data exposure.

Defensive Guidance

No official patch or remediation is indicated for bip39-generator version 3.1.2. Users should immediately remove this malicious package from their projects and replace it with the legitimate bip39 package. Audit dependencies to detect and eliminate typosquatting or malicious packages. Avoid using untrusted or unknown packages, especially those mimicking popular libraries. Monitor for any unauthorized access or credential misuse resulting from the exposure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13257
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a738520bf8831d5394ef8f3

Added to database: 08/05/2026, 18:46:56 UTC

Last enriched: 08/05/2026, 23:00:56 UTC

Last updated: 08/05/2026, 23:14:15 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses