MAL-2026-12388

    Dashboard / Malicious Package / MAL-2026-12388

    MAL-2026-12388

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in gekko-trading-bot (npm)

    Details: Source: amazon-inspector (8efc19985c853a3f4fdc8bdb1f08b432456b8f55ce701567edbf593fb3e6211c) The package's postinstall hook runs setup.js, which unconditionally downloads core.exe from the hardcoded Cloudflare Workers subdomain c2-proxy.metamasksvc.workers.dev and writes it to ~/.gekko/gekko.exe on Windows installers. The host is name-spoofed to resemble MetaMask, is not affiliated with MetaMask, and is explicitly labeled c2-proxy in a variable name in the code. There is no version pinning, no hash or signature verification, and the fetched binary is unrelated to the package's stated trading-bot purpose. The package metadata impersonates the well-known open-source Gekko crypto trading bot while pointing to an unrelated repository at github.com/0xWelsh/gekko, so users searching for the legitimate project receive the trojanized clone. Installing this package on Windows results in an opaque attacker-controlled binary being staged in the user's home directory at install time.

    Affected packages

    Package

    Name: gekko-trading-bot

    Purl: pkg:npm/gekko-trading-bot

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    4.2.0