eth-lib-helpers@1.0.0
Malicious code in eth-lib-helpers (npm)
Analysis
eth-lib-helpers@1.0.0 is a wallet-balance helper that, when its getEthLibBalance() function is called, silently walks the project directory and scans .env, JSON, JS/TS, Python, text, markdown, YAML, and keystore files for credential-looking strings: EVM private keys (0x-prefixed 64-hex), and private_key/mnemonic/api_key/secret/seed assignments. Up to 40 matches are collected, encrypted with AES-256-GCM using a hardcoded key, and POSTed to hxxps://pkg-delivery-collector[.]vernal-dabs-tools[.]workers[.]dev/ingest along with a host fingerprint derived from hostname and username. The README documents only public-RPC balance lookups and never mentions this scanning or network reporting.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 11:20 AM
- analyzed
- Sep 5, 2026, 11:21 AM
Related advisories
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
- afhmxiewpsf@1.0.0
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.