ethereum-kit-1@1.0.0
Malicious code in ethereum-kit-1 (npm)
Analysis
Confirmed crypto wallet stealer. The postinstall hook runs src/index.js which contains a hardcoded Telegram bot token (8227918239:...) and chat ID. It scans the victim's home directory and cwd for Solana (~/.config/solana/id.json), Ethereum keystore, Bitcoin wallet.dat, Tron keystore, SSH keys, and project secrets (.env, wallet.json, mnemonic.txt, seed.txt, etc.), then exfilitrates each found file via api[.]telegram[.]org/bot<TOKEN>/sendDocument. The publisher (aicrypto-xzggz / [account]) and package name ("ethereum-kit-1") are consistent with a combosquat/phishing targeting crypto developers. No token-theft markers for npm/GitHub tokens were found — the attack focuses on crypto wallet theft. This is a true-positive supply-chain attack.
- analyzed by
- Leitwacht
- first seen
- Jun 9, 2026, 02:44 AM
- analyzed
- Jun 9, 2026, 02:45 AM
Related advisories
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
- solana-web3-v1@1.0.0
- solana-web3-lts@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.