Malicious npm Packages Impersonate Flashbots Steal Ethereum Wallet Keys

Four new malicious packages that can steal Ethereum developers’ cryptocurrency wallet credentials have been found in the npm package repository.

According to an investigation by Socket researcher Kush Pandya, the packages pose as trustworthy cryptographic tools and Flashbots MEV infrastructure while surreptitiously transferring private keys and mnemonic seeds to a Telegram bot under the threat actor’s control.

One person, “flashbotts,” uploaded the packages to npm; the oldest library was posted as early as September 2023. August 19, 2025 was the date of the most current upload. The packages in question are mentioned below, and as of this writing, they are all still downloadable:

  • @flashbotts/ethers-provider-bundle (52 Downloads)
  • flashbot-sdk-eth (467 Downloads)
  • sdk-ethers (90 Downloads)
  • gram-utilz (83 Downloads)

Given that Flashbots are used to counteract the negative impacts of Maximal Extractable Value (MEV) on the Ethereum network read more about Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *