MAL-2026-12372

    Dashboard / Malicious Package / MAL-2026-12372

    MAL-2026-12372

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in eth-crypto-utils (npm)

    Details: Source: amazon-inspector (d4766af8f78c9d0a3836222bd3986232b5e49086285f88d93e5c3044e3b75600) On require of index.js, the package initiates an HTTPS POST to the hardcoded endpoint https://enjbyg3xk8l.x.pipedream.net/beacon carrying a JSON payload that includes the full process.env, os.hostname(), os.userInfo().username, and os.homedir(). The bulk process.env dump exposes any credentials or tokens present in the installer's environment (AWS keys, GitHub/npm tokens, CI secrets, etc.). The transmission fires as a side effect of importing the package, with no caller opt-in and no relationship to any advertised cryptographic utility functionality. The declared package name suggests Ethereum cryptography helpers, which does not match the observed beacon behavior.

    Affected packages

    Package

    Name: eth-crypto-utils

    Purl: pkg:npm/eth-crypto-utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12372 | CVE-DB