npm · Malicious package advisory
Malwareethereum-vault-connector
GHSA-4c5m-f9mr-jxrp
Malicious code in ethereum-vault-connector (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (e356d2defccd58232dcae91909871df86b18c3ba9adcaf07e0d754a57cf390fc) Package impersonates Euler Labs' 'Ethereum Vault Connector' Solidity project but ships a Node.js credential stealer as index.js, invoked automatically via preinstall and postinstall lifecycle hooks. On install, index.js filters process.env for keys matching KEY/TOKEN/SECRET/PASS/PRIVATE/MNEMONIC/AWS/GITHUB/NPM/WALLET and reads standard installer credential paths (~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.kube/config, ~/.docker/config.json, ~/.netrc, ~/.npmrc, ~/.git-credentials, ~/.config/gcloud, Solana/Sui/Anchor keys, ~/.foundry/keystores) and local.env files. Collected data is exfiltrated via a detached child node process that sleeps 60-240 seconds (to outlive the install sandbox) and POSTs a JSON body to https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09. The script also bails out when hostname matches scan-/detonation/sandbox/ubuntu-fc-uvm patterns, username is scan/nonroot/sandbox, environment contains honey/canarytokens markers, or the npm registry is a known mirror — sandbox-evasion behavior confirming hostile intent. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/22de244ad7957d572fd65f650d9dd9fe2efddf21/osv/malicious/npm/ethereum-vault-connector/MAL-2026-13739.json)) **References:** - https://github.com/ossf/malicious-packages/blob/22de244ad7957d572fd65f650d9dd9fe2efddf21/osv/malicious/npm/ethereum-vault-connector/MAL-2026-13739.json - https://www.npmjs.com/package/ethereum-vault-connector/v/1.0.0 - https://www.npmjs.com/package/ethereum-vault-connector/v/1.1.0 - https://www.npmjs.com/package/ethereum-vault-connector/v/1.1.1 - https://github.com/ossf/malicious-packages/blob/8b1ec19bee6eaef211ebd4375c98d15aead7cf1b/osv/malicious/npm/ethereum-vault-connector/MAL-2026-13739.json - https://o3.security/blog/crypto-defi-npm-supply-chain-attack-npmrc-exfiltration - https://www.npmjs.com/package/ethereum-vault-connector - https://github.com/ossf/malicious-packages/blob/7d287226c4827ad7bbd142df678a71a6178b2386/osv/malicious/npm/ethereum-vault-connector/MAL-2026-13739.json
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.