Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

The Georgia School District is considering raising property taxes to pay school officials

Democrat government Andy Besher bolsters campaign to secure all four-year-old kindergartens in Kentucky

Trump has promised a green card to international students. Their visas are currently at risk

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Malicious NPM packages target atomic wallets, exodus users by exchanging crypto addresses
Identity

Malicious NPM packages target atomic wallets, exodus users by exchanging crypto addresses

userBy userApril 10, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 10, 2025Ravi LakshmananMalware/Cryptocurrency

Exchange crypto addresses

Threat actors continue to upload malicious packages to the NPM registry, tampering with legitimate libraries of the local version already installed and running malicious code in what is considered a silly attempt to stage software supply chain attacks.

The newly discovered package, named PDF-to-Office, pretends to be a utility for converting PDF files into Microsoft Word documents. However, in reality there is the ability to inject malicious code into atomic wallets and cryptocurrency wallet software related to Exodus.

“In effect, the victim who attempts to send crypto funds to another crypto wallet will have the intended wallet address exchanged with someone belonging to a malicious actor,” Lucija Valentić, a researcher at Reversinglabs, said in a report shared with Hacker News.

Cybersecurity

The NPM package in question was first published on March 24, 2025 and has received three updates since then, but it is not likely that the previous version will be removed by the author himself. The latest version 1.1.2 will be uploaded on April 8th and can be downloaded. The package has been downloaded 334 times so far.

This disclosure comes just weeks after security companies in the software supply chain discovered two NPM packages, named Ethers-Provider2 and Ethers-Providerz, designed to infect locally installed packages and establish a reverse shell that connects to the threat actor’s servers via SSH.

What makes this approach an attractive option for threat actors is that malware can last on developer systems even after malicious packages are removed.

Office analysis from PDF reveals that malicious code embedded in package checks exists in the “Atomic/Resources/App.Asar” archive in the “AppData/Local/Programs” folder.

“If an archive exists, malicious code overwrites one of the files with a new Trojan version with the same functionality as the legitimate file, but has switched the outbound crypto address to which the fund will be sent at the address of a Web3 wallet that is encoded with Base64 belonging to the threat actor,” Valentić said.

Exchange crypto addresses

Similarly, the payload is designed to troilerize the file “SRC/APP/UI/INDEX.js” associated with the Exodus Wallet.

However, with an interesting twist, the attack targets two specific versions, both the atomic wallet (2.91.5 and 2.90.6) and the Exodus (25.13.3 and 25.9.2) to ensure that the correct JavaScript files are overwritten.

“Come to the point, if an office is removed from a packaged PDF from the computer, the software in the Web3 wallet will be compromised and crypto funds will continue to channel into the attacker’s wallet,” Valentić said. “The only way to completely remove malicious Trojanized files from Web3 Wallets software is to completely remove them and reinstall them from your computer.”

This disclosure is provided as a detailed 10 malicious visual studio code extensions with extensibility that disables Windows security, establishes persistence through scheduled tasks, and secretly downloads PowerShell scripts that install XMRIG CryptoMiner.

Cybersecurity

The extension was collectively installed over a million times before it was removed. The extension’s name is as follows:

Beautiful – VSCODE code (clean) Abundant presence of VS code (Mark H) Rojo – Roblox Studio Sync (by Evaera) Solidity Compiler (by Vscode Developer) Claude AI (Mark H) Golang Compiler (Mark H) ChatGPT Agent VSCODE (MARK HTML fuchcator) (by Mark H) vscode rust compiler (by Mark H)

“The attackers created sophisticated multi-stage attacks and installed legitimate extensions they disguised to avoid raising doubt while mining cryptocurrency in the background,” extensionTotal said.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIt is now the real land of freedom
Next Article Early career experts help you land your job with drafted AI and video resumes
user
  • Website

Related Posts

Google publishes vishing group UNC6040 targeting salesforce with fake data loader app

June 4, 2025

Chaos Rat Malware Targets Window and Linux via fake network tools download

June 4, 2025

Why traditional DLP solutions fail in the browser era

June 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Georgia School District is considering raising property taxes to pay school officials

Democrat government Andy Besher bolsters campaign to secure all four-year-old kindergartens in Kentucky

Trump has promised a green card to international students. Their visas are currently at risk

Axiom, a Stanford doctoral student AI startup, raises $50 million at a $300 million valuation

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Axiom, a Stanford doctoral student AI startup, raises $50 million at a $300 million valuation

Reserv raises $25 million Series B to modernize insurance claims with AI and automation

Support Crete to acquire a $500 million accounting firm and promote growth using OpenAI tools

Venmo expands beyond peer-to-peer payments with new debit card rewards and checkout features and becomes a full-service fintech platform

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.