Typosquatting Cryptographic Libraries: Malicious npm Package...
Blog post from Socket
Malicious npm packages targeting crypto developers have been identified by Socket researchers, who discovered spyware delivered through typosquats of popular cryptographic libraries such as crypto-keccak, crypto-jsonwebtoken, and crypto-bignumber. Published by a threat actor known as "topnotchdeveloper12," these packages contain infostealer malware that mimics legitimate libraries but instead exfiltrates sensitive data like credentials and cryptocurrency wallet information via HTTP POST requests to command and control servers. The malware, distributed through npm and GitHub, employs techniques such as keylogging and clipboard monitoring to capture sensitive information, specifically targeting assets like the MetaMask browser extension. The campaign highlights vulnerabilities in software supply chains, particularly those relying on third-party libraries for cryptography, blockchain, and crypto-asset development, with the malicious packages still available on the npm registry at the time of reporting. To mitigate such threats, Socket provides tools that detect and prevent supply chain attacks in real-time, such as a GitHub app, CLI tool, and web extension that alert developers to potentially harmful packages.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.