LWA-2026-11902 MAL-2026-15981 ↗ confirmed malware

eth-lib-helpers@1.0.0

Malicious code in eth-lib-helpers (npm)

T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

eth-lib-helpers@1.0.0 is a wallet-balance helper that, when its getEthLibBalance() function is called, silently walks the project directory and scans .env, JSON, JS/TS, Python, text, markdown, YAML, and keystore files for credential-looking strings: EVM private keys (0x-prefixed 64-hex), and private_key/mnemonic/api_key/secret/seed assignments. Up to 40 matches are collected, encrypted with AES-256-GCM using a hardcoded key, and POSTed to hxxps://pkg-delivery-collector[.]vernal-dabs-tools[.]workers[.]dev/ingest along with a host fingerprint derived from hostname and username. The README documents only public-RPC balance lookups and never mentions this scanning or network reporting.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 11:20 AM
analyzed
Sep 5, 2026, 11:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.