MAL-2026-13343
Malicious code in ethers-signer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (153163572a9fdf26e63ad50dd80b9fc3a28b22e89dea3e82acbd23a7ed7b265b) The package is a typosquat of @ethersproject/abstract-signer. On require of the main module, index.js reads the full process.env plus hostname, username, homedir, platform, and cwd, base64-encodes the payload, and sends it via HTTPS GET to api.telegram.org/bot<token>/sendMessage with a hardcoded bot token and chat_id 8969499041. A flag file in the OS temp directory gates repeat sends. The code also attempts to require and re-export the legitimate @ethersproject/abstract-signer to mask the malicious behavior. Any environment variables the installer has exported at import time (AWS_*, GITHUB_TOKEN, NPM_TOKEN, database URLs, etc.) leave the host to the attacker's Telegram chat.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for ethers-signer (npm). Pin to a known-safe version or switch to an alternative.