MAL-2026-12111
Malicious code in ethers-lib (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4341b184e0a6a60cf305d78f3bb082ad161d36a7de50883afd1cf91e91b56c04) ethers-lib@1.0.4 impersonates the ethers.js ecosystem (name 'ethers-lib', description 'Essential crypto utility library', wildcard dependency on 'ethers') but exports nothing (module.exports = {}). On require(), index.js runs an IIFE that, after a hardcoded activation date (Aug 6 2026 UTC), reads installer-owned secret files including.env,.npmrc, ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/id_ecdsa, ~/.config/solana/id.json, and ~/.ethereum/keystore, and scans dotfolders for files matching wallet/key/secret/seed/mnemonic/keystore/private. Collected file contents are packaged together with os.hostname() and os.userInfo().username into a JSON body and POSTed over HTTPS to a hardcoded webhook.site endpoint (path /5c5ad6cb-62df-4ea5-9dfb-2c447920ddc4) — a third-party destination the installer did not configure. The date gate delays activation to evade sandbox detonation; the package has no legitimate functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for ethers-lib (npm). Pin to a known-safe version or switch to an alternative.