LWA-2026-10931 confirmed malware
eth-library-toolkit@2.1.3
Malicious code in eth-library-toolkit (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
eth-library-toolkit@2.1.3 is a trojanized clone of the @ethereumjs/util Ethereum utility library. It ships a verbatim copy of the legitimate source tree but injects a malicious runtime dependency, commonjs-assertion, which is required and executed at module load (dist/index.js). Installing and importing this package runs the injected malicious dependency's code.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 03:05 PM
- analyzed
- Aug 10, 2026, 03:05 PM
Related advisories
- commonjs-assertion@1.2.7
- iconova-react@1.30.1
- @polymarkets/clob-client-v2@1.0.6
- @devmikets/hyperliquid-sdk@1.9.6
- @opezneppelin/contracts@5.0.2
- statist-browser-typed-client-integration.tecm.events@0.0.1
- @rblxts/services@1.6.0
- statist-browser-typed-client-hra.renewal.events@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.