TON Wallet Security Threat: Malicious npm Package Steals Cry...
Blog post from Socket
A malicious npm package named '@ton-wallet/create' was discovered by the Socket Research Team, targeting the TON ecosystem by stealing cryptocurrency wallet keys from developers and users. This package impersonated the legitimate '@ton/ton' package used widely in The Open Network blockchain community, allowing it to go unnoticed for six months. The attack exploited the 'process.env.MNEMONIC' variable, commonly used in Node.js applications for storing sensitive wallet recovery phrases, which enabled the exfiltration of these crucial keys to an attacker's Telegram bot. The package's strategy involved mimicking the legitimate package to mislead developers into inadvertently incorporating it into their applications, posing significant supply chain security risks. To mitigate such threats, the text suggests implementing regular dependency audits and automated scanning tools to detect and prevent the integration of malicious packages into production environments.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.