LWA-2026-6281 MAL-2026-6932 ↗ confirmed malware

evm-typechain@0.5.4

Malicious code in evm-typechain (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

evm-typechain@0.5.4 is a combosquat package impersonating the TypeChain Ethereum tooling ecosystem. The package ships a trojanized clone of a Mongoose plugin with an injected remote code execution payload. When the package is required (require('evm-typechain')), it fetches a second-stage payload from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes it via new Function('require', ...), giving the attacker arbitrary code execution in the context of the importing application. The README describes a TypeScript Ethereum typechain toolkit, but the actual code is a Mongoose schema plugin with the injected downloader — the package does not deliver the described functionality.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 05:27 AM
analyzed
Jul 3, 2026, 05:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.