“Ethereum signing utility library”
AI
Malicious npm package exfiltrates secrets
Local reference
Suspicious dependency
Inferred
Loading file contents…
Loading traits…
Identity
| SHA-256 | 93384be6ecfc7f978e8ac795226240f95d1482f6c04108b99566751ea31735ef |
|---|---|
| Canonical SHA-256 | 7a77db5e57d58f71f36b6b7b0c0010cb351a33d6855fade3d36a0bb6cfd46590 |
| Filename | ethereum-sign-utils-1.0.0.tgz |
| Package | ethereum-sign-utils |
| Version | 1.0.0 |
| PURL | pkg:npm/[email protected] |
Origin
| Source | forager |
|---|---|
| Feed | osv.dev |
| Ecosystem | javascript |
| Domain | npmmirror.com |
| URL | https://registry.npmmirror.com/ethereum-sign-utils/-/ethereum-sign-utils-1.0.0.tgz |
Timeline
| First seen | 5 Aug 2026 06:23 UTC |
|---|---|
| First analyzed | 5 Aug 2026 12:27 UTC |
| Last analyzed | 5 Aug 2026 12:27 UTC |
| Last updated | 5 Aug 2026 12:27 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | forager |
| Traits version | b5ca8 |
Not seeing what you expected? Let us know