MAL-2026-13937Malicious code in @ethers-js/contracts (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @ethers-js/contracts | 6.9.0 |
{"modified":"2026-08-13T17:17:39Z","published":"2026-08-13T17:17:39Z","schema_version":"1.7.4","id":"MAL-2026-13937","summary":"Malicious code in @ethers-js/contracts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (06aee7d1e943a9d9a705acf4f28286eb5460ab9a56057a0811274787478f7c68)\nPackage impersonates the ethers project (real releases publish under `ethers` and `@ethersproject/*`, not `@ethers-js`). The `postinstall` lifecycle script in scripts/postinstall.js is obfuscated with \\x-hex-encoded identifiers (require('fs'), require('https'), spawn('powershell',...)) and a base64-encoded download URL. On Windows, it decodes the URL to https://files.catbox.moe/7vixtr.zip, downloads the archive into %LOCALAPPDATA%\\Microsoft\\<random>, extracts it via PowerShell Expand-Archive, and then invokes a bundled pythonw.exe against r.py with {detached:true, windowsHide:true} and.unref(), executing attacker-controlled code hidden from the user on `npm install`.\n","affected":[{"package":{"ecosystem":"npm","name":"@ethers-js/contracts"},"versions":["6.9.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/postinstall.js","sha256":"b9ee57b2e1f9a47251422232e370a4574c905b1846bf2138d4443dcdd2a843e1","tlsh":"d541f19571e5a22f23dc49e3fa145ef580a79e12b0c5b043836c794e19e914ac7f5cc8"},{"path":"package.json","sha256":"47b177c142ace98e0bc1bd18a09b7a8181efc164df3f3ca9b3f823e317035a2b","tlsh":"def04c11ca118ea32acc5f805819a58ab561ad0788c87c1a33cb456e5b8f77f01ff5dd"}],"package_integrity":[{"filename":"contracts-6.9.0.tgz","hashes":{"sha1":"68c7a69e015cd42c135e4437778d7f77477bea95","sha512_sri":"sha512-rZVtmt5+rTcSWy7te0PIEoVsTN1gtzb32vSn9+4T0dRlbQsvCZsJiL991aqHe2CL+Qv/nPTTQPAQb+0RFewmXQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ethers-js/contracts/v/6.9.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017648","import_time":"2026-08-13T17:24:45.908276614Z","modified_time":"2026-08-13T17:17:39Z","sha256":"06aee7d1e943a9d9a705acf4f28286eb5460ab9a56057a0811274787478f7c68","source":"amazon-inspector","versions":["6.9.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0