Skip to main content

Threats Tagged 'mal-2026-13738'

View all threats tagged with 'mal-2026-13738'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-13738

Threats Tagged 'mal-2026-13738'

Click on any threat for detailed analysis and mitigation recommendations

@openzeppelin-5/contracts is a malicious npm package published by npm account `mssjeep843` that impersonates OpenZeppelin's `@openzeppelin/contracts` (the v5 line) via the look-alike scope `@openzeppelin-5`, falsely describing itself as a "compatibility distribution". It ships no Solidity contracts — only an install-time payload (index.js) run via preinstall/postinstall that harvests credential-shaped environment variables and reads and exfiltrates SSH private keys, cloud credentials (AWS/GCP/Kubernetes/Docker), Solana/Anchor/NEAR/Sui wallet keys, Foundry keystores, `.git-credentials` and local `.env` files to `https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09`. It is one of a series of DeFi/crypto impersonation packages from the same account sharing this webhook.site endpoint, which also squat Aerodrome Finance, Camelot AMM, Euler EVC, BoringVault and Uniswap Permit2. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (800da818da3fee0353766227eafcd43c0c7cf7fd0126af5ded48b7c1ba522e21) Package name typosquats @openzeppelin/contracts. package.json declares both preinstall and postinstall as `node index.js || true`, so the payload auto-executes on `npm install`. index.js harvests process.env entries matching KEY|TOKEN|SECRET|MNEMONIC|WALLET|AWS|GITHUB|NPM and reads installer-side credential files including ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.kube/config, ~/.docker/config.json, ~/.netrc, ~/.npmrc, ~/.git-credentials, gcloud/solana/sui/foundry keystores, and local.env files. The bundle is POSTed to a hardcoded webhook.site endpoint (path 326b0891-2093-4800-a4c1-686ce3e07b09) via a detached child process spawned with a randomized 60–240 second delay to outlive install-time scanning windows. A hostname regex (/^(scan-|detonation|sandbox|ubuntu-fc-uvm)/i) throws early on known sandbox/scanner hosts as anti-analysis gating.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-13738
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses