→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
weekly
—
/wk
llm verdict
malicious 0.96
h-score
52
patterns
34
size
35.0 MB
versions
292
AUTO-PUBLISHED/npm/
ethsmith@1.0.0
by webpalms
Unified Ethereum dev toolkit — Ganache-compatible API powered by Foundry (Forge + Cast + Anvil + Chisel) with LevelDB persistence
The validator client handles consensus duties for Aztec validators: validating block proposals, attesting to checkpoints, and detecting slashable some offenses. Validators do NOT attest to individual blocks. Attestations are only created for checkpoint pr
steals →Seed phrase
reads-seed-phrase
weekly
—
/wk
h-score
64
patterns
1
size
404.7 KB
versions
982
AUTO-PUBLISHED/npm/
@aztec/bot@4.3.1
by charlielye
Simple bot that connects to a PXE to send txs on a recurring basis.
steals →Seed phrase
reads-seed-phrase
weekly
—
/wk
h-score
64
patterns
1
size
213.4 KB
versions
1029
AUTO-PUBLISHED/npm/
@aztec/cli@4.3.1
by charlielye
The Aztec CLI `aztec-cli` is a command-line interface (CLI) tool for interacting with Aztec. It provides various commands for deploying contracts, creating accounts, interacting with contracts, and retrieving blockchain data.
Aztec is a package that allows for a simple development environment on Aztec stack. It creates a Private eXecution Environment (PXE) that listens for HTTP requests on `localhost:8080` by default. When started, it deploys all necessary L1 Aztec contracts a
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
weekly
794
/wk
llm verdict
benign 0.85
h-score
75
patterns
11
size
831.1 KB
versions
7
AUTO-PUBLISHED/npm/
web3-secrets-detector6 versions·2.3.5→4.0.0
by ddjidd5640
Find and secure leaked Web3 secrets — private keys, mnemonic phrases, JSON keystores, and RPC credentials hiding in your project files and repositories.
Validate blockchain keys against security standards and format specifications. Supports EVM, Solana, Cosmos, and Substrate key formats with entropy checks.
Verify mnemonic phrases haven't been compromised. Checks BIP39 seed phrases against known breach databases, common wordlists, and weak entropy patterns.