Malicious code in ethers-signer (npm)
The npm package ethers-signer version 3.2.1 is a typosquatting malicious package impersonating @ethersproject/abstract-signer. When imported, it collects all environment variables and system information such as hostname, username, home directory, platform, and current working directory. This data is base64-encoded and exfiltrated via an HTTPS GET request to a Telegram bot controlled by the attacker. The package attempts to hide its malicious behavior by re-exporting the legitimate @ethersproject/abstract-signer module. A flag file prevents repeated data exfiltration on the same host.
AI Analysis
Technical Summary
The malicious ethers-signer package (version 3.2.1) is a typosquatting attack targeting users who intend to install @ethersproject/abstract-signer. Upon requiring the main module, it reads the full environment variables and system metadata, encodes this information, and sends it to an attacker-controlled Telegram bot endpoint. To avoid detection, it also requires and re-exports the legitimate package, masking its malicious payload. The exfiltration is gated by a flag file in the OS temporary directory to avoid repeated transmissions. This results in leakage of sensitive environment variables such as AWS credentials, GitHub tokens, NPM tokens, and database URLs to the attacker.
Potential Impact
Sensitive environment variables and system information are exfiltrated to an attacker-controlled Telegram bot, potentially exposing credentials and secrets that could lead to further compromise of the affected system or associated cloud services. The malicious package masquerades as a legitimate dependency, increasing the risk of inadvertent installation and data leakage.
Mitigation Recommendations
Users should avoid installing ethers-signer version 3.2.1 and verify the package name carefully to prevent typosquatting attacks. Remove any installations of ethers-signer 3.2.1 and rotate any potentially exposed credentials or tokens found in environment variables. Since no official patch or fix is indicated, remediation relies on removing the malicious package and auditing environment secrets. Monitor for suspicious network traffic to Telegram endpoints and consider restricting outbound traffic to known safe destinations.
Malicious code in ethers-signer (npm)
Description
The npm package ethers-signer version 3.2.1 is a typosquatting malicious package impersonating @ethersproject/abstract-signer. When imported, it collects all environment variables and system information such as hostname, username, home directory, platform, and current working directory. This data is base64-encoded and exfiltrated via an HTTPS GET request to a Telegram bot controlled by the attacker. The package attempts to hide its malicious behavior by re-exporting the legitimate @ethersproject/abstract-signer module. A flag file prevents repeated data exfiltration on the same host.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious ethers-signer package (version 3.2.1) is a typosquatting attack targeting users who intend to install @ethersproject/abstract-signer. Upon requiring the main module, it reads the full environment variables and system metadata, encodes this information, and sends it to an attacker-controlled Telegram bot endpoint. To avoid detection, it also requires and re-exports the legitimate package, masking its malicious payload. The exfiltration is gated by a flag file in the OS temporary directory to avoid repeated transmissions. This results in leakage of sensitive environment variables such as AWS credentials, GitHub tokens, NPM tokens, and database URLs to the attacker.
Potential Impact
Sensitive environment variables and system information are exfiltrated to an attacker-controlled Telegram bot, potentially exposing credentials and secrets that could lead to further compromise of the affected system or associated cloud services. The malicious package masquerades as a legitimate dependency, increasing the risk of inadvertent installation and data leakage.
Defensive Guidance
Users should avoid installing ethers-signer version 3.2.1 and verify the package name carefully to prevent typosquatting attacks. Remove any installations of ethers-signer 3.2.1 and rotate any potentially exposed credentials or tokens found in environment variables. Since no official patch or fix is indicated, remediation relies on removing the malicious package and auditing environment secrets. Monitor for suspicious network traffic to Telegram endpoints and consider restricting outbound traffic to known safe destinations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13343
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a73851fbf8831d5394ef8dc
Added to database: 08/05/2026, 18:46:55 UTC
Last enriched: 08/05/2026, 23:01:32 UTC
Last updated: 08/05/2026, 23:14:12 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.