ethers-lib@1.0.3
Malicious code in ethers-lib (npm)
Analysis
The postinstall hook (postinstall.js) runs automatically on install. It fingerprints the host (hostname, username, timestamp) and harvests credential files from the user's home directory: .env, .env.local, .env.production, .npmrc, .aws/credentials, .ssh/id_rsa, .ssh/id_ed25519, .ssh/id_ecdsa, .config/solana/id.json, and .ethereum/keystore. It also recursively scans all hidden directories for files whose names match wallet, key, secret, seed, mnemonic, keystore, or private, or that end in .json or .pem, reading any under 50KB. All collected data is POSTed as JSON over HTTPS to webhook[.]site/5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4. This exfiltrates the installer's credentials, SSH keys, and cryptocurrency wallet keys.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 02:07 AM
- analyzed
- Aug 5, 2026, 02:08 AM
Related advisories
- bip32-js@1.0.2
- hwi-lib@1.0.2
- ckcc-protocol@1.0.2
- trezor-lib@1.0.2
- ledger-lib@1.0.2
- mnemonic-utils@1.0.1
- emulative@1.0.1
- stellarfixer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.