LWA-2026-3387 MAL-2026-5355 ↗ confirmed malware

ethereum-kit-1@1.0.0

Malicious code in ethereum-kit-1 (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

Confirmed crypto wallet stealer. The postinstall hook runs src/index.js which contains a hardcoded Telegram bot token (8227918239:...) and chat ID. It scans the victim's home directory and cwd for Solana (~/.config/solana/id.json), Ethereum keystore, Bitcoin wallet.dat, Tron keystore, SSH keys, and project secrets (.env, wallet.json, mnemonic.txt, seed.txt, etc.), then exfilitrates each found file via api[.]telegram[.]org/bot<TOKEN>/sendDocument. The publisher (aicrypto-xzggz / [account]) and package name ("ethereum-kit-1") are consistent with a combosquat/phishing targeting crypto developers. No token-theft markers for npm/GitHub tokens were found — the attack focuses on crypto wallet theft. This is a true-positive supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 9, 2026, 02:44 AM
analyzed
Jun 9, 2026, 02:45 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.