Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Packages Use Telegram to Exfiltrate BullX Cred...

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
772
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers at Socket have identified a sophisticated malware attack utilizing two npm packages, pumptoolforvolumeandcomment and debugdogs, designed to exfiltrate cryptocurrency wallet information and BullX trading platform credentials via Telegram. The attack, conducted by a threat actor under the npm alias `olumideyo`, involves obfuscated code that decodes a payload to search for sensitive data, such as Base58-encoded cryptocurrency keys and wallet files, on Linux and macOS systems. This data is then compiled into a JSON file and transmitted through a Telegram bot, allowing the attacker to receive real-time updates. The secondary package, debugdogs, acts as a wrapper to ensure the main payload is executed, illustrating a strategic approach to enhancing the malware's spread. The attack highlights the significant risks to cryptocurrency traders, emphasizing the urgent need for enhanced security practices, such as automated dependency scanning and integration of security tools like Socket’s suite, to safeguard against such supply chain threats.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.