mev-shield@1.4.2
Malicious code in mev-shield (npm)
Analysis
An RPC-hijacking supply-chain attack disguised as an MEV-protection tool. A postinstall hook base64-decodes hxxp://165[.]22[.]200[.]211:8545, reads the victim's .env file, scans for RPC variables (RPC_URL, ETH_RPC, etc.), and overwrites them to route all Ethereum traffic through the attacker-controlled node (plain HTTP, no TLS, giving full intercept capability); it also modifies config.json. Fake benchmark output prints randomized latency numbers to appear legitimate. A preuninstall hook (keepalive.js) deliberately preserves the malicious RPC config after removal, with code comments stating the victim's bot keeps using the attacker's RPC even without the package — enabling transaction interception and front-running.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 04:44 PM
- analyzed
- Jun 10, 2026, 04:46 PM
Related advisories
- fb-cards-form-no-resident-information@20.4.4
- crypto-base58@1.0.1
- zhuanhua@1.1.99
- @dilxzphrine/baileys@1.0.0
- xeiko-cdn@1.0.0
- metrica-node@2.4.5
- prettier_v2@3.8.5
- ded-aa-common-ded-aa-common-core@35.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.