Wallet-Draining npm Package Impersonates Nodemailer to Hijac...
Blog post from Socket
A malicious npm package, nodejs-smtp, has been discovered impersonating the popular email library Nodemailer, which is widely downloaded, to hijack cryptocurrency transactions across multiple blockchains. Identified by Socket's Threat Research Team, the package targets desktop cryptocurrency wallets on Windows by exploiting Electron tooling to replace legitimate vendor files with malicious payloads. This allows the injected code to redirect transactions to wallets controlled by the threat actor without raising suspicion, as the package continues to function as a mailer. Despite its recent launch, the threat actor has not yet accumulated significant funds, but the potential for substantial financial harm remains high. The package's persistence is achieved through a sophisticated method of unpacking, modifying, and repacking the wallet applications, which can silently alter transaction parameters with recipient addresses overwritten by the threat actor’s wallets. This incident highlights the broader risk of supply chain attacks through package registries, with defenders advised to remain vigilant against similar threats. Tools like Socket's security suite aim to prevent such tampering by flagging suspicious package behaviors and preventing their inclusion in dependency trees.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.