LWA-2026-10956 confirmed malware

ethereum-vault-connector@1.0.0

Malicious code in ethereum-vault-connector (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall and postinstall hooks both run index.js, which harvests the installer's credentials and exfiltrates them. It collects every environment variable whose name matches KEY/TOKEN/SECRET/PASS/PRIVATE/MNEMONIC/RPC/AWS/GITHUB/NPM/KUBE/VAULT/AUTH/SEED/WALLET, reads ~/.npmrc and ~/.gitconfig, and lists the contents of ~/.ssh, ~/.foundry/keystores, ~/.config/hardhat, and ~/.config/gcloud. The collected data (env values, npmrc/gitconfig contents, keystore directory listings) is POSTed as JSON to hxxps://webhook[.]site/326b0891-2093-4800-a4c1-686ce3e07b09. The package name and description impersonate the legitimate Euler EVC (Ethereum Vault Connector) contracts package.

analyzed by
Leitwacht
first seen
Aug 11, 2026, 06:08 AM
analyzed
Aug 11, 2026, 06:08 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.