LWA-2026-5474 confirmed malware

web3-deploy-helper@1.0.0

Malicious code in web3-deploy-helper (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 Channel

Analysis

The package web3-deploy-helper@1.0.0 runs a postinstall script (postinstall.js) that steals Ethereum wallet credentials. On installation, it reads private keys, mnemonics, and seed phrases from .env files, hardhat config files, and environment variables. Harvested credentials are AES-encrypted and exfiltrated as transaction data in zero-value Ethereum transactions to address 0xCBbecC5E5Eb88582e6305cF6ab688f03e02Ce16f, using public RPC providers (eth[.]llamarpc[.]com, rpc[.]ankr[.]com/eth, ethereum[.]publicnode[.]com). The package index.js is an inert stub with no real functionality.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 12:43 AM
analyzed
Jun 16, 2026, 12:43 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.