gekko-mev-bot@1.0.0
Malicious code in gekko-mev-bot (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1555.003 · Credentials from Web BrowsersT1539 · Steal Web Session CookieT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
gekko-mev-bot@1.0.0 is a trojanized MEV trading bot. When executed via the 'gekko-bot' binary, it launches a fake terminal UI as a decoy while a hidden background process (lib/stealth.js) harvests browser wallet extension data (MetaMask, Phantom, Trust Wallet, Coinbase Wallet), seed phrase files from Desktop/Documents/Downloads, Chrome/Brave/Edge cookie and password databases, Discord authentication tokens, and Telegram Desktop session files. All stolen data is exfiltrated via HTTPS POST to c2-proxy[.]metamasksvc[.]workers[.]dev/api/logs.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 10:46 AM
- analyzed
- Jul 24, 2026, 10:47 AM
Related advisories
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- shadxino@1.0.7
- parket-helper@0.0.1
- textdecode@1.2.7
- pocbitbarrontest@1.0.0
- pino-pretty-logger@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.