LWA-2026-10931 confirmed malware

eth-library-toolkit@2.1.3

Malicious code in eth-library-toolkit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

eth-library-toolkit@2.1.3 is a trojanized clone of the @ethereumjs/util Ethereum utility library. It ships a verbatim copy of the legitimate source tree but injects a malicious runtime dependency, commonjs-assertion, which is required and executed at module load (dist/index.js). Installing and importing this package runs the injected malicious dependency's code.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 03:05 PM
analyzed
Aug 10, 2026, 03:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.