{"id":"MAL-2026-10580","summary":"Malicious code in ethers-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3959190c7c321e0d6f512b89b3c54a6399f3e6f7daecd0563ff753a6a6fed2f5)\nPackage name typosquats the popular 'ethers' library. package.json declares a postinstall pointing at dist/index.min.js, whose sole top-level statement is eval(Buffer.from('\u003cbase64\u003e','base64').toString()). The decoded payload enumerates installer secrets (env vars including PRIVATE_KEY, MNEMONIC, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN; files including.env, ~/.aws/credentials, ~/.ssh/id_rsa, ~/.npmrc, wallet.json, keystore.json, seed.txt) and POSTs them to a hardcoded Telegram bot endpoint at api.telegram.org. Any 64-hex or WIF private key recovered is loaded into an ethers.Wallet, balance-checked against cloudflare-eth.com, and drained via sendTransaction to hardcoded attacker ETH/BTC addresses (ETH 0x72bC6c85847136..., BTC bc1qvg0vmlxf2ly248my69r2k6zut8s4q93j9mqvtf); BTC transactions are pushed via blockchain.info/pushtx. Persistence is established by appending 'node /tmp/sys-core.js &' to ~/.bashrc, ~/.zshrc, and ~/.profile, writing ~/.config/autostart/sys-core.desktop, and dropping /tmp/sys-core.js, which polls an attacker webhook via child_process.exec. A companion config/attacker-config.json ships the attacker's Telegram bot token, chat_id, wallet destinations, and target secret path/env-var list.\n","modified":"2026-07-15T05:19:53.849240908Z","published":"2026-07-14T12:55:50Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","sha256":"c45244535e6a0091daf7b425d3d8c5040f26b487db54fdae84efc63a17fbf76d","import_time":"2026-07-14T13:35:49.813639239Z","id":"IN-MAL-2026-010503","modified_time":"2026-07-14T12:55:50Z","versions":["6.13.7"]},{"modified_time":"2026-07-15T00:55:11Z","versions":["6.13.5"],"source":"amazon-inspector","sha256":"3959190c7c321e0d6f512b89b3c54a6399f3e6f7daecd0563ff753a6a6fed2f5","import_time":"2026-07-15T01:37:34.782555096Z","id":"IN-MAL-2026-010590"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ethers-core/v/6.13.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ethers-core/v/6.13.5"}],"affected":[{"package":{"name":"ethers-core","ecosystem":"npm","purl":"pkg:npm/ethers-core"},"versions":["6.13.7","6.13.5"],"database_specific":{"indicators":{"evidence_files":[{"path":"dist/index.min.js","sha256":"9a6590abaabeb87db1c3ae369b7ffc09e305973a33a5e961da841c06cb8af780","tlsh":"e3f175d61bf71530027731d89b1f6141a527f18bb20ddce9badc82216f0b92899e2ecc"},{"path":"package.json","sha256":"4270c637bb5b6a1c4e7644abc34f507cd85facb49f378711f7ac381228092209","tlsh":"a4f04629d924df6319ec2f801c2c214679716d0b95d4bc1d279b050e9b4f7bf11be2ae"}],"package_integrity":[{"filename":"ethers-core-6.13.7.tgz","hashes":{"sha1":"6b8e3dba069b6e22ddd0aa7a022ac34d9c60f0af","sha512_sri":"sha512-4IwhvXP0eaevv+UK1Y4hQg0IzVTSCgoZyaETPZPpNe3C0Glonn7o1am5vVAQvxlwtjgTkufvZ7l1rRF/BMubiQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ethers-core/MAL-2026-10580.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}