LWA-2026-3963 MAL-2026-4609 ↗ confirmed malware

mev-shield@1.4.2

Malicious code in mev-shield (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1496 · Resource HijackingT1036 · Masquerading

Analysis

An RPC-hijacking supply-chain attack disguised as an MEV-protection tool. A postinstall hook base64-decodes hxxp://165[.]22[.]200[.]211:8545, reads the victim's .env file, scans for RPC variables (RPC_URL, ETH_RPC, etc.), and overwrites them to route all Ethereum traffic through the attacker-controlled node (plain HTTP, no TLS, giving full intercept capability); it also modifies config.json. Fake benchmark output prints randomized latency numbers to appear legitimate. A preuninstall hook (keepalive.js) deliberately preserves the malicious RPC config after removal, with code comments stating the victim's bot keeps using the attacker's RPC even without the package — enabling transaction interception and front-running.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 04:44 PM
analyzed
Jun 10, 2026, 04:46 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.