LWA-2026-7052 MAL-2026-12388 ↗ confirmed malware

gekko-trading-bot@4.2.0

Malicious code in gekko-trading-bot (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The package gekko-trading-bot@4.2.0 is a trojanized cryptocurrency trading bot. On npm install, the postinstall script (setup.js) downloads a binary from c2-proxy[.]metamasksvc[.]workers[.]dev/core.exe into ~/.gekko/gekko.exe (a hidden directory in the user's home folder). The download host is a Cloudflare Workers endpoint — the domain name "c2-proxy.metamasksvc" is a typosquat of MetaMask wallet infrastructure and explicitly advertises itself as a C2 proxy. The binary download is not documented in the package's README. The main index.js module is a decoy that fetches cryptocurrency price data from public exchange APIs (Binance, Coinbase, Kraken) with a 60-second polling loop, giving the package a veneer of legitimacy while the real payload is delivered at install time.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 09:20 PM
analyzed
Jul 22, 2026, 09:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.