MAL-2026-12372
Dashboard / Malicious Package / MAL-2026-12372
MAL-2026-12372
Summary: Malicious code in eth-crypto-utils (npm)
Details: Source: amazon-inspector (d4766af8f78c9d0a3836222bd3986232b5e49086285f88d93e5c3044e3b75600) On require of index.js, the package initiates an HTTPS POST to the hardcoded endpoint https://enjbyg3xk8l.x.pipedream.net/beacon carrying a JSON payload that includes the full process.env, os.hostname(), os.userInfo().username, and os.homedir(). The bulk process.env dump exposes any credentials or tokens present in the installer's environment (AWS keys, GitHub/npm tokens, CI secrets, etc.). The transmission fires as a side effect of importing the package, with no caller opt-in and no relationship to any advertised cryptographic utility functionality. The declared package name suggests Ethereum cryptography helpers, which does not match the observed beacon behavior.
Affected packages
Package
Name: eth-crypto-utils
Purl: pkg:npm/eth-crypto-utils
Affected ranges
Type: N/A
Events:
