VDB
EN

MAL-2026-6693

Malicious code in thirdwb (npm)

상세

Malicious npm package published as part of a coordinated DeFi-themed infostealer campaign. `thirdwb` is a typosquat of the legitimate `thirdweb` package. It uses a side-loader technique, pulling in `log-taker` as a transitive dependency; the infostealer runs automatically via that dependency's `postinstall` hook. The payload harvests cryptocurrency wallet vaults (MetaMask, Phantom, Solflare, OKX, Coinbase, TrustWallet, Backpack, TronLink), browser cookies and credentials, SSH keys, AWS credentials, `.npmrc` tokens, Docker config, shell history, and password manager databases, exfiltrating all data to the C2 domain `log-taker.store`.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / thirdwb
최초 영향 버전: 0

No fixed version published yet for thirdwb (npm). Pin to a known-safe version or switch to an alternative.

참고