Four malicious npm packages are stealing Ethereum devs’ wallet keys. They pose as Flashbots tools—but secretly send your private keys + seeds to a Telegram bot. One package even reroutes unsigned transactions to an attacker’s wallet. Still live on npm right now. Details here ↓