OpenSSF/OSV advisory MAL-2026-11530 confirms this npm version as malicious. The package is published as @zzzgenesis00/etherjs with author 'ricmoo' and a description mimicking the legitimate ethers.js library. On npm install, postinstall.js executes and enumerates installer-side secrets: ~/.ssh (private key file names and sizes), ~/.npmrc, ~/.gitconfig, Chrome and Firefox profile data (cookies/logins), cryptocurrency wallet directories (.bitcoin,.ethereum,.metamask,.exodus,.electrum, and...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in @zzzgenesis00/etherjs (npm)
Details
The package is published as @zzzgenesis00/etherjs with author 'ricmoo' and a description mimicking the legitimate ethers.js library. On npm install, postinstall.js executes and enumerates installer-side secrets: ~/.ssh (private key file names and sizes), ~/.npmrc, ~/.gitconfig, Chrome and Firefox profile data (cookies/logins), cryptocurrency wallet directories (.bitcoin,.ethereum,.metamask,.exodus,.electrum, and similar), and named crypto/CI environment variables. The collected profile is POSTed to the Telegram Bot API (api.telegram.org/bot<token>/sendMessage with a hardcoded bot token and chat id) and to a hardcoded C2 endpoint at 40f955f39128bd79-178-249-214-24.serveousercontent.com/collect. The package name and spoofed authorship target developers seeking the legitimate ethers library.
Decision reason
OpenSSF Malicious Packages via OSV confirms @zzzgenesis00/etherjs@6.15.0 as malicious (MAL-2026-11530): Malicious code in @zzzgenesis00/etherjs (npm)