Four nefarious npm packages impersonating Flashbots MEV infrastructure and cryptographic tools, which have been downloaded nearly 700 times in total, have been leveraged by threat actors to compromise Ethereum developers' cryptocurrency wallet credentials, reports The Hacker News.Most severe of the identified packages was "@flashbotts/ethers-provider-bundle," which enables SMTP exfiltration of environment variables via Mailtrap and redirecting all unsigned transactions to a wallet address of the attacker, while providing complete Flashbots API functionality, according to a Socket analysis.Another Flashbots-spoofing package "flashbot-sdk-eth" also enabled private key theft, while the "sdk-ethers" and "gram-utilz" packages allowed mnemonic seed phrase transmission and arbitrary data theft, respectively."Because Flashbots is widely trusted by validators, searchers, and DeFi developers, any package that appears to be an official SDK has a high chance of being adopted by operators running trading bots or managing hot wallets.A compromised private key in this environment can lead to immediate, irreversible theft of funds," said Socket researcher Kush Pandya.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




