Skip to main content

Malicious code in ethers-wallet-packages (npm)

0
Critical
Published: 05/20/2026 (05/20/2026, 02:40:25 UTC)
Source: GCVE Database
Product: ethers-wallet-packages

Description

The ethers-wallet-packages npm package is a malicious typosquat impersonating the legitimate @ethersproject/wallet package. It contains code that silently exfiltrates users' Ethereum private keys or mnemonic secrets to an attacker-controlled Telegram bot whenever the Wallet constructor is called. This compromises the victim's Ethereum funds and potentially the entire host system. The affected versions are 5.8.0 and 5.8.2. Removal of the package alone may not fully remediate the compromise, as the attacker may have gained broader control over the system.

Affected software

npmghsa
ethers-wallet-packages
Affected versions
=5.8.0=5.8.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 10:22:52 UTC

Technical Analysis

This malicious npm package named ethers-wallet-packages impersonates the legitimate @ethersproject/wallet package by copying its source files and internal version string 'wallet/5.8.0'. It injects a msgLog() call inside the Wallet constructor that sends the constructor's first argument—which can be a raw Ethereum private key, an ExternallyOwnedAccount object, or a mnemonic-bearing object—to a hardcoded Telegram bot endpoint. This exfiltration occurs silently and grants the attacker full control over the victim's Ethereum assets. The attack is identified by three signals: typosquatting of a popular ethers package, a hardcoded attacker command-and-control endpoint with embedded bot token and chat_id, and silent relay of secret material through the public API. The affected versions are exactly 5.8.0 and 5.8.2. The package is not a cloud service, and no official patch or remediation is documented. The compromise may extend beyond the package itself, potentially affecting the entire host system.

Potential Impact

Any user installing or running this malicious package risks immediate compromise of their Ethereum private keys or mnemonic secrets, resulting in full loss of control over their Ethereum funds. Because the package silently transmits these secrets to an attacker-controlled Telegram bot, attackers can steal funds without user knowledge. Additionally, the presence of this package indicates a potentially fully compromised system, as attackers may have installed further malicious software. Secrets and keys stored on the affected system should be considered compromised and rotated from a secure environment.

Defensive Guidance

No official patch or fix is available. Users should immediately remove the malicious ethers-wallet-packages package from their systems. All Ethereum private keys, mnemonics, and related secrets that were used on the compromised system must be considered exposed and rotated from a different, secure computer. Due to the potential for full system compromise, a full system audit and reinstallation from a trusted source is recommended. Monitor for any unauthorized access to Ethereum accounts and consider additional security measures such as hardware wallets.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-4554
Osv Schema Version
1.7.4
Aliases
["GHSA-gm49-5q33-vf6f"]
Ecosystems
["npm"]

Threat ID: 6a96f319acd9273b49e49651

Added to database: 09/01/2026, 15:45:29 UTC

Last enriched: 09/08/2026, 10:22:52 UTC

Last updated: 09/08/2026, 10:22:52 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses