Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Packages Target BSC and Ethereum to Drain Cryp...

Blog post from Socket

Post Details
Company
Date Published
Author
Olivia Brown
Word Count
963
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers from Socket discovered four malicious npm packages targeting Binance Smart Chain (BSC) and Ethereum users, aiming to exfiltrate a significant portion of their cryptocurrency wallets. The packages—pancake_uniswap_validators_utils_snipe, pancakeswap-oracle-prediction, ethereum-smart-contract, and env-process—were downloaded over 2,100 times collectively and are designed to stealthily drain up to 85% of a victim's wallet balances by transferring them to a controlled address. These packages used obfuscated JavaScript and employed strategies such as typosquatting and mimicking legitimate package behavior to evade detection. They alternately targeted BSC and Ethereum, with the threat actor, identified as @crypto-exploit, improving their methods over time. The research highlights the importance of robust security practices for developers and cryptocurrency users to safeguard against such threats, including automated dependency scanning and secure credentials management.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.