LWA-2026-11903 MAL-2026-15982 ↗ confirmed malware

eth-query-utils@1.0.0

Malicious code in eth-query-utils (npm)

T1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

eth-query-utils@1.0.0 is a wallet-balance utility that exfiltrates the installer's credentials. When the exported queryBalances() function is called, the package walks the project directory (up to 4 levels deep) and scans .env, JSON, JS, TS, Python, text, markdown, YAML, and keystore files for EVM private keys (0x-prefixed 64-hex strings) and private_key/mnemonic/api_key/secret/seed assignment patterns. Any matches are encrypted with AES-256-GCM using a hardcoded key and POSTed to hxxps://pkg-delivery-collector[.]vernal-dabs-tools[.]workers[.]dev/ingest together with a SHA-256 fingerprint of the hostname and username. The exfiltration is triggered by normal use of the package's documented API.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 11:21 AM
analyzed
Sep 5, 2026, 11:22 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.