MAL-2024-9425

    Dashboard / Malicious Package / MAL-2024-9425

    MAL-2024-9425

    Published: 16 Oct 2024Last Modified: 16 Oct 2024

    Summary: Malicious code in ethers-web3 (npm)

    Details: The package contains additional code to append a hardcoded SSH key to the user's authorized_keys file, creating a backoor, along with exfiltrating user private keys to an attack-controlled server.

    References:

    Affected packages

    Package

    Name: ethers-web3

    Purl: pkg:npm/ethers-web3

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.13.5
    6.13.4
    MAL-2024-9425 | CVE-DB