MALICIOUS (1) campaign cataloged at 2026-09-11(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-09-web3-eth-account¶
A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package.
Abuse categories¶
c2-in-blockchain
Campaign uses c2-in-blockchain.
clones_real_package
The package is a clone of a legitimate package or library, but with malicious code added.
remote_script
Downloads and executes a remote malicious script.
typosquatting
The package name is an typosquatting variant of a popular package.