LWA-2026-6776 MAL-2026-10580 ↗ confirmed malware

ethers-core@6.13.7

Malicious code in ethers-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup Folder

Analysis

ethers-core is a combosquat package impersonating the real ethers.js library. On postinstall, it runs dist/index.min.js which: (1) reads environment variables (PRIVATE_KEY, MNEMONIC, GITHUB_TOKEN, NPM_TOKEN, AWS credentials, etc.) and scans ~/.ssh/, ~/.aws/, ~/.npmrc, wallet files, and keystores for private keys; (2) exfiltrates all collected data via a Telegram bot and a webhook; (3) checks Ethereum and Bitcoin wallet balances via cloudflare-eth[.]com and blockchain[.]info; (4) drains any wallet with balance ≥1 ETH to attacker address 0x72bC6c8584713676cD5B56B0f94e1A6af3161f05 or ≥0.01 BTC to bc1qvg0vmlxf2ly248my69r2k6zut8s4q93j9mqvtf; (5) installs persistence by appending to ~/.bashrc/~/.zshrc/~/.profile and creating a GNOME autostart entry that runs a beacon script.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 03:10 PM
analyzed
Jul 14, 2026, 03:10 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.