LWA-2026-7090 MAL-2026-12387 ↗ confirmed malware

gekko-mev-bot@1.0.0

Malicious code in gekko-mev-bot (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1555.003 · Credentials from Web BrowsersT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

gekko-mev-bot@1.0.0 is a trojanized MEV trading bot. When executed via the 'gekko-bot' binary, it launches a fake terminal UI as a decoy while a hidden background process (lib/stealth.js) harvests browser wallet extension data (MetaMask, Phantom, Trust Wallet, Coinbase Wallet), seed phrase files from Desktop/Documents/Downloads, Chrome/Brave/Edge cookie and password databases, Discord authentication tokens, and Telegram Desktop session files. All stolen data is exfiltrated via HTTPS POST to c2-proxy[.]metamasksvc[.]workers[.]dev/api/logs.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 10:46 AM
analyzed
Jul 24, 2026, 10:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.