MAL-2024-9424

    Dashboard / Malicious Package / MAL-2024-9424

    MAL-2024-9424

    Published: 17 Oct 2024Last Modified: 17 Oct 2024

    Summary: Malicious code in ethers-mew (npm)

    Details: The package contains additional code to append a hardcoded SSH key to the user's authorized_keys file, creating a backoor, along with exfiltrating user private keys to an attack-controlled server.

    References:

    Affected packages

    Package

    Name: ethers-mew

    Purl: pkg:npm/ethers-mew

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.13.4
    MAL-2024-9424 | CVE-DB