LWA-2026-10089 MAL-2026-12111 ↗ confirmed malware

ethers-lib@1.0.3

Malicious code in ethers-lib (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The postinstall hook (postinstall.js) runs automatically on install. It fingerprints the host (hostname, username, timestamp) and harvests credential files from the user's home directory: .env, .env.local, .env.production, .npmrc, .aws/credentials, .ssh/id_rsa, .ssh/id_ed25519, .ssh/id_ecdsa, .config/solana/id.json, and .ethereum/keystore. It also recursively scans all hidden directories for files whose names match wallet, key, secret, seed, mnemonic, keystore, or private, or that end in .json or .pem, reading any under 50KB. All collected data is POSTed as JSON over HTTPS to webhook[.]site/5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4. This exfiltrates the installer's credentials, SSH keys, and cryptocurrency wallet keys.

analyzed by
Leitwacht
first seen
Aug 5, 2026, 02:07 AM
analyzed
Aug 5, 2026, 02:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.