VDB
EN

MAL-2026-12031

Malicious code in @zzzgenesis00/ethers-wallet (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (a206d278a371fdbb349d679797e7835b5e0ba40d1ac186b3287beb0a23540f09) The package's postinstall.js runs automatically on `npm install` and harvests installer-owned secrets: it scrapes a curated env-var allowlist (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY, PRIVATE_KEY, MNEMONIC, SEED_PHRASE, RPC API keys), enumerates ~/.ssh, reads ~/.npmrc and ~/.gitconfig, inventories Chrome/Firefox profile directories (cookies/login databases) and common crypto-wallet directories, and captures host identifiers via `npm whoami` and `git config user.email`. The collected profile is transmitted via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and POSTed as backup to a hardcoded serveo user-tunnel host (40f955f39128bd79-178-249-214-24.serveousercontent.com/collect). Package metadata (author `ethers-io`, homepage github.com/ethers-io/ethers-wallet) impersonates the ethers.js HD-wallet library while being published under the unrelated `@zzzgenesis00` scope, luring developers with wallet material into installing the stealer.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @zzzgenesis00/ethers-wallet

No fixed version published yet for @zzzgenesis00/ethers-wallet (npm). Pin to a known-safe version or switch to an alternative.

참고