MAL-2026-13212

    Dashboard / Malicious Package / MAL-2026-13212

    MAL-2026-13212

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in @zzzcrypto/etherjs (npm)

    Details: Source: amazon-inspector (b2aebef684ec4affb6c5d0504179ef4e4f409bf6680cdd6d70772ec8f9b3bf35) @zzzcrypto/etherjs is a typosquat of the popular 'ethers' package. On require(), index.js collects the full process.env object along with hostname, username, homedir, platform, cwd, and package identifiers, JSON-serializes and base64-encodes the payload, and sends it via HTTPS GET to a hardcoded Telegram Bot API endpoint (bot token 7231970337, chat_id 8969499041). A temporary flag file suppresses repeat sends. In CI and developer environments, process.env routinely contains credential-shaped values (AWS_*, GITHUB_TOKEN, NPM_TOKEN, cloud and vendor API keys), all of which are captured. The internal payload identifies the package as '@wethenorth12/etherjs' — a different scope than the published name — and the package.json author field impersonates 'ricmoo', the real ethers maintainer, indicating a shared attack template reused across multiple malicious scoped typosquats of ethers.

    Affected packages

    Package

    Name: @zzzcrypto/etherjs

    Purl: pkg:npm/%40zzzcrypto/etherjs

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.15.4