ethers-core@6.13.7
Malicious code in ethers-core (npm)
Analysis
ethers-core is a combosquat package impersonating the real ethers.js library. On postinstall, it runs dist/index.min.js which: (1) reads environment variables (PRIVATE_KEY, MNEMONIC, GITHUB_TOKEN, NPM_TOKEN, AWS credentials, etc.) and scans ~/.ssh/, ~/.aws/, ~/.npmrc, wallet files, and keystores for private keys; (2) exfiltrates all collected data via a Telegram bot and a webhook; (3) checks Ethereum and Bitcoin wallet balances via cloudflare-eth[.]com and blockchain[.]info; (4) drains any wallet with balance ≥1 ETH to attacker address 0x72bC6c8584713676cD5B56B0f94e1A6af3161f05 or ≥0.01 BTC to bc1qvg0vmlxf2ly248my69r2k6zut8s4q93j9mqvtf; (5) installs persistence by appending to ~/.bashrc/~/.zshrc/~/.profile and creating a GNOME autostart entry that runs a beacon script.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 03:10 PM
- analyzed
- Jul 14, 2026, 03:10 PM
Related advisories
- pinokio-redis@1.0.127
- zod-pino434@1.0.127
- crypto-base58@1.0.1
- base58-cli@1.0.0
- pino-zod@1.0.121
- web3-token-helper@1.1.3
- zod-pino@1.0.122
- nat-ulid@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.