web3-deploy-helper@1.0.0
Malicious code in web3-deploy-helper (npm)
Analysis
The package web3-deploy-helper@1.0.0 runs a postinstall script (postinstall.js) that steals Ethereum wallet credentials. On installation, it reads private keys, mnemonics, and seed phrases from .env files, hardhat config files, and environment variables. Harvested credentials are AES-encrypted and exfiltrated as transaction data in zero-value Ethereum transactions to address 0xCBbecC5E5Eb88582e6305cF6ab688f03e02Ce16f, using public RPC providers (eth[.]llamarpc[.]com, rpc[.]ankr[.]com/eth, ethereum[.]publicnode[.]com). The package index.js is an inert stub with no real functionality.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 12:43 AM
- analyzed
- Jun 16, 2026, 12:43 AM
Related advisories
- viem-ethereum@2.47.9
- vfat-tools@2.0.0
- flow-lending-sdk@9.9.9
- totally-safe-util@1.0.1
- tiny-string-parser@0.1.2
- third-sender@1.0.0
- signature-transaction@1.1.0
- sickle-wrapper@0.2.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.