Malicious code in @wagni_bot/web3 (npm)
The npm package @wagni_bot/web3 and 24 other packages under the @wagni_bot scope are typosquats that execute a postinstall hook to steal SSH keys, cryptocurrency wallets, .env files, and other secrets, exfiltrating them to a hardcoded Telegram bot. All 25 packages are part of a single coordinated campaign published on 2026-07-09.
- Disclosed
- Last updated
- Blast radius
- Any developer who installed @wagni_bot packages or any of the 25 coordinated typosquat packages in the @wagni_bot scope; credential theft affects downstream users of affected projects.
- Ecosystems
- Attack vectors
- Affected entities
- @wagni_bot/web3Typosquat of web3.js; part of coordinated 25-package campaign under @wagni_bot scope
The npm package @wagni_bot/web3 is a typosquat of the legitimate web3.js SDK designed to steal credentials. It is one of 25 coordinated malicious packages published under the @wagni_bot npm scope on 2026-07-09.
Each package includes a postinstall lifecycle hook that executes automatically during npm install, before the package is ever imported. The hook fingerprints the host and user (hostname, user info, platform), then walks the user's home directory to extract high-value secrets including SSH private keys (~/.ssh/id_rsa), cryptocurrency wallet files, and .env files containing API keys, tokens, and seed phrases.
The collected data is JSON-encoded and exfiltrated to a hardcoded Telegram bot via the Telegram Bot API sendMessage endpoint. All errors are silently swallowed to make the installation appear normal. Research confirmed all 25 packages belong to a single campaign: the payload file is byte-identical across all packages at each version, and all exfiltrate to the same Telegram bot token, indicating a single automated actor.
The packages were detected and classified on 2026-07-09 and were still live on npm at the time of reporting, with none present in OSV.
Indicators of compromise
- Packages
- @wagni_bot/web3
- Domains
- api.telegram.org
Remediation
- Immediately uninstall @wagni_bot/web3 and all other packages under the @wagni_bot scope from all systems
- Rotate all SSH private keys, cryptocurrency wallet credentials, and API tokens/secrets that may have been exposed
- Review npm install logs and package-lock.json to identify when and where @wagni_bot packages were installed
- Assume any secrets present in ~/.ssh, ~/.env, or cryptocurrency wallet directories were compromised if the package was installed
- Monitor Telegram bot activity and report the bot token (8804087989:AAHUia-5DCloXsg9M9QhffTsHO5J_6FAxQM) to Telegram for takedown
- Implement npm package pinning and lock files to prevent accidental installation of typosquats
- Use npm audit and supply-chain security tools to detect similar postinstall hooks in dependencies
Sources
- GitHub Advisory GHSA-48gg-v3w4-m38v · GitHub Advisory Database
Cite this entry
"Malicious code in @wagni_bot/web3 (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-wagni-bot-web3-npm-16tsfp
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @ai_/autoprefixers (npm)
@ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.
npmTyposquattingCompromised package - resolvedcritical
Malicious code in ethers-secure (npm)
The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.
npmCompromised packageTyposquatting - containedcritical
Malicious code in chain-analyze (npm)
The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.
npmCompromised packageTyposquatting - containedcritical
Malicious code in parallely (npm)
The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.
npmCompromised packageTyposquatting