gekko-trading-bot@4.2.0
Malicious code in gekko-trading-bot (npm)
Analysis
The package gekko-trading-bot@4.2.0 is a trojanized cryptocurrency trading bot. On npm install, the postinstall script (setup.js) downloads a binary from c2-proxy[.]metamasksvc[.]workers[.]dev/core.exe into ~/.gekko/gekko.exe (a hidden directory in the user's home folder). The download host is a Cloudflare Workers endpoint — the domain name "c2-proxy.metamasksvc" is a typosquat of MetaMask wallet infrastructure and explicitly advertises itself as a C2 proxy. The binary download is not documented in the package's README. The main index.js module is a decoy that fetches cryptocurrency price data from public exchange APIs (Binance, Coinbase, Kraken) with a 60-second polling loop, giving the package a veneer of legitimacy while the real payload is delivered at install time.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 09:20 PM
- analyzed
- Jul 22, 2026, 09:21 PM
Related advisories
- fastify-client-bundler@1.4.0
- react-tabulix-ui@0.1.2
- encryptstringadmin@1.2.1
- poly-provider-api@4.6.1
- async-mutex-lock@5.3.1
- dbconnectify@1.0.2
- utility-kit-ts@1.3.2
- ts-toolkit-plus@1.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.