logo

Malicious npm packages target Ethereum developers' private keys

ID: af16c5c9-a386-5687-8e73-c77bf436fd59

STIX ID: report--af16c5c9-a386-5687-8e73-c77bf436fd59

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-01-03

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Malicious typosquatting npm packages impersonating the Hardhat development environment have been published to steal Ethereum developer secrets—private keys, mnemonics, and config files—by collecting the data via Hardhat runtime hooks, encrypting it with a hardcoded AES key, and exfiltrating it to attacker-controlled endpoints; the campaign comprises 20 packages with over 1,000 downloads and poses a tangible risk of wallet theft and supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.