eth-query-utils@1.0.0
Malicious code in eth-query-utils (npm)
Analysis
eth-query-utils@1.0.0 is a wallet-balance utility that exfiltrates the installer's credentials. When the exported queryBalances() function is called, the package walks the project directory (up to 4 levels deep) and scans .env, JSON, JS, TS, Python, text, markdown, YAML, and keystore files for EVM private keys (0x-prefixed 64-hex strings) and private_key/mnemonic/api_key/secret/seed assignment patterns. Any matches are encrypted with AES-256-GCM using a hardcoded key and POSTed to hxxps://pkg-delivery-collector[.]vernal-dabs-tools[.]workers[.]dev/ingest together with a SHA-256 fingerprint of the hostname and username. The exfiltration is triggered by normal use of the package's documented API.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 11:21 AM
- analyzed
- Sep 5, 2026, 11:22 AM
Related advisories
- eth-lib-helpers@1.0.0
- gas-price-checker@1.0.0
- @lekzo_dev/amprem@1.0.4
- afhmxiewpsf@1.0.0
- 2nestjs@0.0.1
- 1nestjs@0.0.1
- 0nestjs@0.0.1
- @quantixfinance/database@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.