evm-typechain@0.5.4
Malicious code in evm-typechain (npm)
Analysis
evm-typechain@0.5.4 is a combosquat package impersonating the TypeChain Ethereum tooling ecosystem. The package ships a trojanized clone of a Mongoose plugin with an injected remote code execution payload. When the package is required (require('evm-typechain')), it fetches a second-stage payload from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes it via new Function('require', ...), giving the attacker arbitrary code execution in the context of the importing application. The README describes a TypeScript Ethereum typechain toolkit, but the actual code is a Mongoose schema plugin with the injected downloader — the package does not deliver the described functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 05:27 AM
- analyzed
- Jul 3, 2026, 05:28 AM
Related advisories
- polygon-gamma-apis@1.5.2
- polygon-gama-apis@1.4.1
- notifier-utils@1.3.7
- chai-chain-dom@1.3.7
- better-tailwindcss@4.6.3
- transform-es2015-sticky-regex@6.24.3
- chai-await-dom@1.3.7
- chai-as-align@7.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.