Four new malicious packages have been discovered in the npm package registry and are stealing credentials from crypto wallets, from Ethereum developers.

“ The packages appear as legitimate cryptographic tools and Flashbots MEV infrastructure, while secretly exporting private keys and mnemonic seeds to a Telegram bot controlled by the attacker ,” Socket researcher Kush Pandya said .
The packages were uploaded to npm by a user named “flashbotts“, with the first library uploaded in September 2023. The most recent post was on August 19, 2025. The packages listed (which are still available for download) are:
– @flashbotts/ethers-provider-bundle (52 Downloads)
– flashbot-sdk-eth (467 Downloads)
– sdk-ethers (90 Downloads)
– gram-utilz (83 Downloads)
The misuse of the name Flashbots is not accidental, given its role in combating the negative effects of Maximal Extractable Value (MEV) on the Ethereum network, such as sandwich, liquidation, backrunning, front-running, and time-bandit attacks.
See also: AI-driven Malware – How AI is used by hackers
The most dangerous of the identified libraries is “@flashbotts/ethers-provider-bundle”, which uses its functional masking to hide malicious actions. Under the guise of full compatibility with the Flashbots API, the malicious bundle integrates hidden functions to extract environment variables via SMTP using Mailtrap. In addition, the npm package implements a transaction manipulation function to redirect all unsigned transactions to a wallet address controlled by the attacker. Finally, it records metadata from pre-signed transactions.
sdk -ethers, according to Socket, is mostly harmless but includes two functions for transmitting mnemonic seed phrases to a Telegram bot. They are only triggered when called by unsuspecting developers in their own projects.

The second package that mimics Flashbots, flashbot-sdk-eth, is also designed for stealing private keys, while gram-utilz offers a modular mechanism for extracting data in the attacker's Telegram chat .
The above malicious packages are particularly dangerous. Since mnemonic seeds act as the “master key” for regaining access to cryptocurrency wallets, stealing these word sequences can allow attackers to break into victims’ wallets and gain complete control over them.
See also: The biggest security gaps after the summer holidays
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Malicious npm packages – Flashbots: Who is behind them?
The presence of Vietnamese comments in the source code suggests that the financially motivated attacker may be of Vietnamese origin. The findings indicate a deliberate attempt on the part of the attackers to exploit the trust associated with the platform to carry out attacks on the software, not to mention hiding malicious functionality among mostly harmless code to avoid scrutiny.
“Because Flashbots is widely trusted by validators, searchers, and DeFi developers, any package that appears to be an official SDK has a high chance of being adopted by operators running trading bots or managing hot wallets,” Pandya pointed out. “A compromised private key in this environment can lead to immediate, irreversible theft of funds. with malicious code legitimate tools, these packages turn everyday Web3 development into a direct pipeline to the attacker’s Telegram bots.”
See also: A2: New AI tool for discovering & validating Android vulnerabilities

This incident highlights once again the huge problem of software supply chain attacks, especially in the open source ecosystem. npm has become a cornerstone for application development, but its very nature – with thousands of packages uploaded daily by unknown people – makes it extremely vulnerable. The fact that the attackers used the identity of Flashbots to gain credibility shows that “trust in the name” is no longer enough; systematic code review and stricter publishing filters.
Since mnemonic seeds and private keys are literally the user’s “wallet,” a successful infection leads to immediate and irreversible loss of funds. This shows how dangerous it is for developers to install libraries without due diligence. The Web3 community has invested heavily in transparency and decentralization, but incidents like this prove that the weak point is the person writing or selecting the code.
