Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

Blog post from Socket

Post Details
Company
Date Published
Author
Joseph Edwards
Word Count
1,101
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

On July 7, 2026, Socket's AI scanner identified a malware campaign targeting SDK developers and users of the PaySafe, Skrill, and Neteller payment applications via npm and PyPI packages. A total of 17 malicious packages were published almost simultaneously, with npm packages having four versions and PyPI packages one version each, aiming to steal credentials and tokens by exfiltrating them to AWS infrastructure. The malicious npm packages mimic legitimate Paysafe REST clients to steal API keys and other sensitive data, employing techniques to evade sandbox detection and obfuscate the Command and Control (C2) domain using a multi-step decoding process. The PyPI packages exhibit similar behavior without requiring API keys, activating based on their placement in the code. The malware campaign demonstrates advanced attributes, such as targeting financial SDKs, using unique obfuscation keys, leveraging Ngrok infrastructure, and showing awareness of sandbox evasion tactics, indicating a sophisticated threat actor potentially linked to established cybercrime networks. To mitigate the threat, it is recommended to rotate all secrets on compromised machines, block the malicious packages at the registry proxy level, and audit CI logs and network traffic for indicators of compromise.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 2,479 445 126 -1%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.