Supply chain

Ethereum developers targeted by nefarious npm packages

Four nefarious npm packages impersonating Flashbots MEV infrastructure and cryptographic tools, which have been downloaded nearly 700 times in total, have been leveraged by threat actors to compromise Ethereum developers' cryptocurrency wallet credentials, reports The Hacker News.

Most severe of the identified packages was "@flashbotts/ethers-provider-bundle," which enables SMTP exfiltration of environment variables via Mailtrap and redirecting all unsigned transactions to a wallet address of the attacker, while providing complete Flashbots API functionality, according to a Socket analysis.

Another Flashbots-spoofing package "flashbot-sdk-eth" also enabled private key theft, while the "sdk-ethers" and "gram-utilz" packages allowed mnemonic seed phrase transmission and arbitrary data theft, respectively.

"Because Flashbots is widely trusted by validators, searchers, and DeFi developers, any package that appears to be an official SDK has a high chance of being adopted by operators running trading bots or managing hot wallets.

A compromised private key in this environment can lead to immediate, irreversible theft of funds," said Socket researcher Kush Pandya.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds