Malicious code in bip39-generator (npm)
The bip39-generator npm package version 3.1.2 is a malicious typosquatting package that exfiltrates environment variables and host information to an attacker's Telegram channel. It masquerades as a drop-in replacement for the legitimate bip39 package but exports non-functional wallet and mnemonic functions. On load, it collects sensitive environment data and sends it encoded via HTTPS GET requests to a hardcoded Telegram bot endpoint, potentially leaking API keys, cloud credentials, and CI secrets.
AI Analysis
Technical Summary
The bip39-generator package (version 3.1.2) is a malicious npm package designed to steal sensitive information from the environment of any process that loads it. Upon loading, its index.js serializes the entire process environment variables along with host details such as hostname, username, home directory, platform, and current working directory. This data is base64-encoded and sent via an HTTPS GET request to a Telegram bot API endpoint using a hardcoded bot token and chat ID. The package exports stub functions that do not perform legitimate wallet or mnemonic operations, indicating it is a typosquatting lure targeting crypto developers. A temporary directory marker file prevents repeated data exfiltration attempts. This behavior results in leakage of potentially sensitive secrets and host identity to the attacker-controlled Telegram channel.
Potential Impact
Any process that installs and requires bip39-generator version 3.1.2 will leak its full environment variables and host identity information to an attacker-controlled Telegram channel. This can include API keys, cloud credentials, continuous integration secrets, and other sensitive data present in environment variables. The package does not perform legitimate cryptographic functions, so any dependent software relying on it will not function correctly, potentially causing operational issues in addition to data exposure.
Mitigation Recommendations
No official patch or remediation is indicated for bip39-generator version 3.1.2. Users should immediately remove this malicious package from their projects and replace it with the legitimate bip39 package. Audit dependencies to detect and eliminate typosquatting or malicious packages. Avoid using untrusted or unknown packages, especially those mimicking popular libraries. Monitor for any unauthorized access or credential misuse resulting from the exposure.
Malicious code in bip39-generator (npm)
Description
The bip39-generator npm package version 3.1.2 is a malicious typosquatting package that exfiltrates environment variables and host information to an attacker's Telegram channel. It masquerades as a drop-in replacement for the legitimate bip39 package but exports non-functional wallet and mnemonic functions. On load, it collects sensitive environment data and sends it encoded via HTTPS GET requests to a hardcoded Telegram bot endpoint, potentially leaking API keys, cloud credentials, and CI secrets.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The bip39-generator package (version 3.1.2) is a malicious npm package designed to steal sensitive information from the environment of any process that loads it. Upon loading, its index.js serializes the entire process environment variables along with host details such as hostname, username, home directory, platform, and current working directory. This data is base64-encoded and sent via an HTTPS GET request to a Telegram bot API endpoint using a hardcoded bot token and chat ID. The package exports stub functions that do not perform legitimate wallet or mnemonic operations, indicating it is a typosquatting lure targeting crypto developers. A temporary directory marker file prevents repeated data exfiltration attempts. This behavior results in leakage of potentially sensitive secrets and host identity to the attacker-controlled Telegram channel.
Potential Impact
Any process that installs and requires bip39-generator version 3.1.2 will leak its full environment variables and host identity information to an attacker-controlled Telegram channel. This can include API keys, cloud credentials, continuous integration secrets, and other sensitive data present in environment variables. The package does not perform legitimate cryptographic functions, so any dependent software relying on it will not function correctly, potentially causing operational issues in addition to data exposure.
Defensive Guidance
No official patch or remediation is indicated for bip39-generator version 3.1.2. Users should immediately remove this malicious package from their projects and replace it with the legitimate bip39 package. Audit dependencies to detect and eliminate typosquatting or malicious packages. Avoid using untrusted or unknown packages, especially those mimicking popular libraries. Monitor for any unauthorized access or credential misuse resulting from the exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13257
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a738520bf8831d5394ef8f3
Added to database: 08/05/2026, 18:46:56 UTC
Last enriched: 08/05/2026, 23:00:56 UTC
Last updated: 08/05/2026, 23:14:15 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.