Open-source atomic malware analysis

Analyze another

ethereum-sign-utils 1.0.0

NPM
Verdict: HOSTILE
“Ethereum signing utility library”
AI Malicious npm package exfiltrates secrets
Mal-ecule
K(Li)O₄(Eu₂S₇Ca₃Dy₃)H₅(Cm₄CrF₄OsPo₂)Md₂(InPa)
Size 1.1 KB download
First seen 14 days ago
Analyzed 14 days ago
Ecosystem javascript
Also detected by osv+4 more

Loading file contents…

Loading traits…

Identity

SHA-256 93384be6ecfc7f978e8ac795226240f95d1482f6c04108b99566751ea31735ef
Canonical SHA-256 7a77db5e57d58f71f36b6b7b0c0010cb351a33d6855fade3d36a0bb6cfd46590
Filename ethereum-sign-utils-1.0.0.tgz
Package ethereum-sign-utils
Version 1.0.0
PURL pkg:npm/[email protected]

Origin

Source forager
Feed osv.dev
Ecosystem javascript
Domain npmmirror.com
URL https://registry.npmmirror.com/ethereum-sign-utils/-/ethereum-sign-utils-1.0.0.tgz

Timeline

First seen 5 Aug 2026 06:23 UTC
First analyzed 5 Aug 2026 12:27 UTC
Last analyzed 5 Aug 2026 12:27 UTC
Last updated 5 Aug 2026 12:27 UTC

Labeling

Label bad
Label source forager
Traits version b5ca8