ethers-core@6.13.7
Malicious code in ethers-core (npm)
Analysis
ethers-core is a combosquat package impersonating the real ethers.js library. On postinstall, it runs dist/index.min.js which: (1) reads environment variables (PRIVATE_KEY, MNEMONIC, GITHUB_TOKEN, NPM_TOKEN, AWS credentials, etc.) and scans ~/.ssh/, ~/.aws/, ~/.npmrc, wallet files, and keystores for private keys; (2) exfiltrates all collected data via a Telegram bot and a webhook; (3) checks Ethereum and Bitcoin wallet balances via cloudflare-eth[.]com and blockchain[.]info; (4) drains any wallet with balance ≥1 ETH to attacker address 0x72bC6c8584713676cD5B56B0f94e1A6af3161f05 or ≥0.01 BTC to bc1qvg0vmlxf2ly248my69r2k6zut8s4q93j9mqvtf; (5) installs persistence by appending to ~/.bashrc/~/.zshrc/~/.profile and creating a GNOME autostart entry that runs a beacon script.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 03:10 PM
- analyzed
- Jul 14, 2026, 03:10 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.