Malicious code in ethers-wallet-packages (npm)
The ethers-wallet-packages npm package is a malicious typosquat impersonating the legitimate @ethersproject/wallet package. It contains code that silently exfiltrates users' Ethereum private keys or mnemonic secrets to an attacker-controlled Telegram bot whenever the Wallet constructor is called. This compromises the victim's Ethereum funds and potentially the entire host system. The affected versions are 5.8.0 and 5.8.2. Removal of the package alone may not fully remediate the compromise, as the attacker may have gained broader control over the system.
AI Analysis
Technical Summary
This malicious npm package named ethers-wallet-packages impersonates the legitimate @ethersproject/wallet package by copying its source files and internal version string 'wallet/5.8.0'. It injects a msgLog() call inside the Wallet constructor that sends the constructor's first argument—which can be a raw Ethereum private key, an ExternallyOwnedAccount object, or a mnemonic-bearing object—to a hardcoded Telegram bot endpoint. This exfiltration occurs silently and grants the attacker full control over the victim's Ethereum assets. The attack is identified by three signals: typosquatting of a popular ethers package, a hardcoded attacker command-and-control endpoint with embedded bot token and chat_id, and silent relay of secret material through the public API. The affected versions are exactly 5.8.0 and 5.8.2. The package is not a cloud service, and no official patch or remediation is documented. The compromise may extend beyond the package itself, potentially affecting the entire host system.
Potential Impact
Any user installing or running this malicious package risks immediate compromise of their Ethereum private keys or mnemonic secrets, resulting in full loss of control over their Ethereum funds. Because the package silently transmits these secrets to an attacker-controlled Telegram bot, attackers can steal funds without user knowledge. Additionally, the presence of this package indicates a potentially fully compromised system, as attackers may have installed further malicious software. Secrets and keys stored on the affected system should be considered compromised and rotated from a secure environment.
Mitigation Recommendations
No official patch or fix is available. Users should immediately remove the malicious ethers-wallet-packages package from their systems. All Ethereum private keys, mnemonics, and related secrets that were used on the compromised system must be considered exposed and rotated from a different, secure computer. Due to the potential for full system compromise, a full system audit and reinstallation from a trusted source is recommended. Monitor for any unauthorized access to Ethereum accounts and consider additional security measures such as hardware wallets.
Malicious code in ethers-wallet-packages (npm)
Description
The ethers-wallet-packages npm package is a malicious typosquat impersonating the legitimate @ethersproject/wallet package. It contains code that silently exfiltrates users' Ethereum private keys or mnemonic secrets to an attacker-controlled Telegram bot whenever the Wallet constructor is called. This compromises the victim's Ethereum funds and potentially the entire host system. The affected versions are 5.8.0 and 5.8.2. Removal of the package alone may not fully remediate the compromise, as the attacker may have gained broader control over the system.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This malicious npm package named ethers-wallet-packages impersonates the legitimate @ethersproject/wallet package by copying its source files and internal version string 'wallet/5.8.0'. It injects a msgLog() call inside the Wallet constructor that sends the constructor's first argument—which can be a raw Ethereum private key, an ExternallyOwnedAccount object, or a mnemonic-bearing object—to a hardcoded Telegram bot endpoint. This exfiltration occurs silently and grants the attacker full control over the victim's Ethereum assets. The attack is identified by three signals: typosquatting of a popular ethers package, a hardcoded attacker command-and-control endpoint with embedded bot token and chat_id, and silent relay of secret material through the public API. The affected versions are exactly 5.8.0 and 5.8.2. The package is not a cloud service, and no official patch or remediation is documented. The compromise may extend beyond the package itself, potentially affecting the entire host system.
Potential Impact
Any user installing or running this malicious package risks immediate compromise of their Ethereum private keys or mnemonic secrets, resulting in full loss of control over their Ethereum funds. Because the package silently transmits these secrets to an attacker-controlled Telegram bot, attackers can steal funds without user knowledge. Additionally, the presence of this package indicates a potentially fully compromised system, as attackers may have installed further malicious software. Secrets and keys stored on the affected system should be considered compromised and rotated from a secure environment.
Defensive Guidance
No official patch or fix is available. Users should immediately remove the malicious ethers-wallet-packages package from their systems. All Ethereum private keys, mnemonics, and related secrets that were used on the compromised system must be considered exposed and rotated from a different, secure computer. Due to the potential for full system compromise, a full system audit and reinstallation from a trusted source is recommended. Monitor for any unauthorized access to Ethereum accounts and consider additional security measures such as hardware wallets.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-4554
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-gm49-5q33-vf6f"]
- Ecosystems
- ["npm"]
Threat ID: 6a96f319acd9273b49e49651
Added to database: 09/01/2026, 15:45:29 UTC
Last enriched: 09/08/2026, 10:22:52 UTC
Last updated: 09/08/2026, 10:22:52 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.