Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

An important part of enterprise AI governance

Ukrainian Network FDN3 launches massive brute force attacks on SSL VPN and RDP devices

£104 million boosts local transport to transform UK communities

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Malicious NPM Package nodejs-smtp mimic nodemailer, target atomic and exodus wallet
Identity

Malicious NPM Package nodejs-smtp mimic nodemailer, target atomic and exodus wallet

userBy userSeptember 2, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 2, 2025Ravi LakshmananCryptocurrency/Malware

Cybersecurity researchers have discovered a malicious NPM package with stealth capabilities to inject malicious code into desktop apps for cryptocurrency wallets such as Atomic and Exodus on Windows systems.

A package named NodeJS-SMTP disguises legitimate email library node mail with the same catchphrase, page styling and README descriptions, and has collected a total of 347 downloads since it was uploaded to the NPM registry in April 2025 by a user named “Nikotimon.” It is currently no longer available.

“In import, the package uses electronic tools to unpack the app in the atomic wallet, replace the vendor bundle with a malicious payload, repackage the application, remove the working directory and remove the trace.”

CIS Build Kit

The main purpose is to overwrite recipient addresses with hardcoded wallets controlled by threat actors, and to redirect Bitcoin (BTC), Ethereum (ETH), Tether (USDT and TRX USDT), XRP (XRP), and Solana (SOL) transactions.

That being said, this package provides specified functionality by acting as an SMTP-based mailer to avoid any developer doubt.

The package still acts as a mailer and exposes a drop-in interface that is compatible with nodemailer. Its feature cover reduces doubt, passes application tests, and has little reason to raise developers question their dependencies.

The development comes months after ReverSingLabs discovered an NPM package named “PDF-to-Office.” This achieved the same goal by unpacking the “app.asar” archives associated with Atomic and Exodus wallets and modifying the JavaScript file to introduce clipper functions.

“This campaign shows how routine imports to developer workstations can quietly modify other desktop applications and maintain them throughout the entire reboot,” Boychenko said. “By running import times and abuse electronic packages, a look-like mailer becomes a wallet drainer that transforms atomic and exit on compromised Windows systems.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUS and India’s VCS had just formed an alliance of over $1 billion to fund deep tech startups in India
Next Article Reinventing optical networks to promote the future of 6G
user
  • Website

Related Posts

An important part of enterprise AI governance

September 2, 2025

Ukrainian Network FDN3 launches massive brute force attacks on SSL VPN and RDP devices

September 2, 2025

Silver Fox Exploit Microsoft Signature Watchdog Driver Deploys ValleyRat Malware

September 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

An important part of enterprise AI governance

Ukrainian Network FDN3 launches massive brute force attacks on SSL VPN and RDP devices

£104 million boosts local transport to transform UK communities

Research reveals the effects of electrical discharge on satellites

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Beyond Compliance: The New Era of Smart Medical Device Software Integration

Unlocking Tomorrow’s Health: Medical Device Integration

Web 3.0’s Promise: What Sir Tim Berners-Lee Envisions for the Future of the Internet

TwinH’s Paves Way at Break The Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.