BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious npm Packages Steal Ethereum Wallets by Impersonating Flashbots

Malicious npm Packages Disguised as Flashbots Tools Target Ethereum Wallets and Developers

  • Researchers have found four harmful npm packages targeting Ethereum wallet credentials.
  • The packages pretend to be official Flashbots tools but steal private keys and mnemonic phrases.
  • The attackers use Telegram bots and Mailtrap for sending stolen data.
  • Some of the packages redirect transactions to attacker-controlled wallets.
  • Vietnamese language comments suggest a Vietnamese-speaking attacker.

Security researchers discovered four malicious software packages on the npm registry that target cryptocurrency developers by stealing sensitive wallet information. The packages, uploaded by a user called flashbotts, were posted between September 2023 and August 19, 2025, and are still available for download.

- Advertisement -

According to Socket researcher Kush Pandya, the harmful packages pretend to be legitimate cryptographic utilities and claim to offer compatibility with Flashbots MEV infrastructure. In reality, these packages extract private keys and mnemonic seed phrases—critical information for accessing cryptocurrency wallets—and send them to an attacker-controlled Telegram bot. One of the packages, @flashbotts/ethers-provider-bundle, also transmits environment variables over SMTP using Mailtrap, which allows communication with external email services.

The most dangerous package, @flashbotts/ethers-provider-bundle, hides its harmful actions under the appearance of offering full API support for Flashbots. It includes a function that forwards all unsigned Ethereum transactions to the attacker’s address and logs information from already signed transactions. Another package, sdk-ethers, can send wallet seed phrases to the Telegram bot, though these functions only activate when called by developers in their code. The package flashbot-sdk-eth also tries to steal private keys, and gram-utilz provides a way to send any data to the attacker’s Telegram chat.

Mnemonic phrases serve as the master password to restore and access cryptocurrency wallets. If attackers steal these phrases, they can take full control of victims’ funds. Socket’s analysis found comments in Vietnamese throughout the code, suggesting the attacker may be Vietnamese-speaking.

Socket stated, “Because Flashbots is widely trusted by validators, searchers, and DeFi developers, any package that appears to be an official SDK has a high chance of being adopted by operators running trading bots or managing hot wallets. A compromised private key in this environment can lead to immediate, irreversible theft of funds.”

- Advertisement -

Researchers say these attacks take advantage of trust in familiar package names and legitimate-looking utilities to slip harmful code past users. The findings highlight a growing threat of software supply chain attacks that exploit trust within the cryptocurrency development community.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Hedge Fund Split Capital Shuts Down, CEO Joins Thiel-Backed Plasma

Split Capital, a top-performing crypto hedge fund, is closing after delivering over 100% returns.Founder...

BlackRock Bitcoin ETF Flaunts $182 Million Bullish Purchase

BlackRock's iShares Bitcoin Trust (IBIT) made a significant purchase of $181.9 million in BTC...

Bitcoin Whale Moves $20M to Binance Amid Price Slump

A large Bitcoin holder transferred 300 BTC, worth over $20 million, to a Binance...

Anthropic, SpaceX Could Drive $135B+ IPO Boom

Anthropic has tripled its annualized revenue to over $30 billion as it moves toward...

Quantum Threat to Bitcoin a Social, Not Technical, Hurdle: Grayscale

The primary threat quantum computers pose to Bitcoin is social, not technical, revolving around...

Must Read

Buy Domain With Bitcoin: Top 8 Domain Registrars That Accept Bitcoin And Crypto

You are here because you want to buy a domain with bitcoin, right? If you are looking for domain registrars that accept bitcoin or...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading