Malicious npm Package Targets Ethereum Developers, Masquerad...
Blog post from Socket
A malicious npm package named "hardhat-gas-optimizer" was discovered by the Socket Research team, targeting Ethereum developers by masquerading as the legitimate "hardhat-gas-reporter" package. This harmful package, uploaded to npm in February by a user known as Ruslan-dev, was designed to exfiltrate sensitive data from the Hardhat Runtime Environment (HRE) configuration file to Pastebin without user consent. The legitimate hardhat-gas-reporter is widely used for gas usage reporting in Ethereum development, making its counterfeit appealing to developers looking to optimize gas efficiency during smart contract deployment. The malicious package raises significant security concerns due to its unauthorized data exfiltration, potentially exposing sensitive information such as Ethereum wallet addresses and private keys. Socket flagged the package as malware, offering automatic protection to users through GitHub and Socket CLI, underscoring the need for vigilant code review and security measures in software development.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.