Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds

CryptoExpert by CryptoExpert
April 15, 2025
in Ethereum News
0
Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds
  • Facebook
  • Twitter
  • Pinterest



You might also like

CME’s 24/7 crypto launch will kill Bitcoin’s weekend gap, but Monday now matters more

Ethereum Bull David Hoffman Shares Why He Sold His ETH

Ethereum Pushes Privacy Forward: EIP-8182 Eyes Hegota Upgrade Integration

Researchers have discovered a malicious software package uploaded to npm that secretly alters locally installed versions of crypto wallets and allows attackers to intercept and reroute digital currency transactions, ReversingLabs revealed in a recent report.

The campaign injected trojanized code into locally installed Atomic and Exodus wallet software and hijacked crypto transfers. The attack centered on a deceptive npm package, pdf-to-office, which posed as a library for converting PDF files to Office formats.

When executed, the package silently located and modified specific versions of Atomic and Exodus wallets on victims’ machines, redirecting outgoing crypto transactions to wallets controlled by threat actors.

ReversingLabs said the campaign exemplifies a broader shift in tactics: rather than directly compromising open-source libraries, which often triggers swift community responses, attackers are increasingly distributing packages designed to “patch” local installations of trusted software with stealthy malware.

Tokenmetrics

Targeted file patching

The pdf-to-office package was first uploaded to npm in March and updated multiple times through early April. Despite its stated function, the package lacked actual file conversion features.

Instead, its core script executed obfuscated code that searched for local installations of Atomic Wallet and Exodus Wallet and overwrote key application files with malicious variants.

The attackers replaced legitimate JavaScript files inside the resources/app.asar archive with near-identical trojanized versions that substituted the user’s intended recipient address with a base64-decoded wallet belonging to the attacker.

For Atomic Wallet, versions 2.90.6 and 2.91.5 were specifically targeted. Meanwhile, a similar method was applied to Exodus Wallet versions 25.9.2 and 25.13.3.

Once modified, the infected wallets would continue redirecting funds even if the original npm package was deleted. Full removal and reinstallation of the wallet software were required to eliminate the malicious code.

ReversingLabs also noted the malware’s attempts at persistence and obfuscation. Infected systems sent installation status data to an attacker-controlled IP address (178.156.149.109), and in some cases, zipped logs and trace files from AnyDesk remote access software were exfiltrated, suggesting an interest in deeper system infiltration or evidence removal.

Expanding software supply chain threats

The discovery follows a similar March campaign involving ethers-provider2 and ethers-providerz, which patched the ethers npm package to establish reverse shells. Both incidents highlight the rising complexity of supply chain attacks targeting the crypto space.

ReversingLabs warned that these threats continue to evolve, especially in web3 environments where local installations of open-source packages are common. Attackers increasingly rely on social engineering and indirect infection methods, knowing that most organizations fail to scrutinize already installed dependencies.

According to the report:

“This kind of patching attack remains viable because once the package is installed and the patch is applied, the threat persists even if the source npm module is removed.”

The malicious package was flagged by ReversingLabs’ machine-learning algorithms under Threat Hunting policy TH15502. It has since been removed from npm, but a republished version under the same name and version 1.1.2 briefly reappeared, indicating the threat actor’s persistence.

Investigators published hashes of affected files and wallet addresses used by the attackers as indicators of compromise (IOCs). These include wallets used for illicit fund redirection, as well as the SHA1 fingerprints of all infected package versions and associated trojanized files.

As software supply chain attacks become more frequent and technically refined, especially in the digital asset space, security experts are calling for stricter code auditing, dependency management, and real-time monitoring of local application changes.

Mentioned in this article



Source link

  • Facebook
  • Twitter
  • Pinterest
CryptoExpert

CryptoExpert

Recommended For You

CME’s 24/7 crypto launch will kill Bitcoin’s weekend gap, but Monday now matters more

by CryptoExpert
May 28, 2026
0
Hut 8 AI landlord data center strategy turns Bitcoin collateral into bridge capital

CME gaps are supposed to die Friday.CME Group says its regulated crypto futures and options will move to 24-hour, seven-day trading on May 29, pending regulatory review, cutting...

Read more

Ethereum Bull David Hoffman Shares Why He Sold His ETH

by CryptoExpert
May 27, 2026
0
Cointelegraph

David Hoffman, an Ethereum advocate and the co-founder of the media company Bankless, says he sold the remainder of his Ether (ETH) holdings last week as he believes...

Read more

Ethereum Pushes Privacy Forward: EIP-8182 Eyes Hegota Upgrade Integration

by CryptoExpert
May 26, 2026
0
Ethereum Pushes Privacy Forward: EIP-8182 Eyes Hegota Upgrade Integration

Key Highlights EIP-8182 introduces protocol-level private ETH transactions to Ethereum’s core infrastructure. The Hegota upgrade may incorporate a unified shielded pool for enhanced privacy features. EIP-8182 addresses the...

Read more

Ethereum Foundation Will Sell Less ETH As It Narrows Mission

by CryptoExpert
May 25, 2026
0
Vitalik Says Ethereum Foundation Will Sell Less ETH As It Narrows Mission

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Vitalik Buterin said the Ethereum Foundation (EF) is moving toward a smaller, more focused and...

Read more

Bitcoin’s hard-money thesis is colliding with 5% Treasury yields

by CryptoExpert
May 24, 2026
0
Bitcoin’s hard-money thesis is colliding with 5% Treasury yields

Make CryptoSlate preferred on Bitcoin was created as a response to the kind of debt-financed monetary disorder now playing out across global bond markets. The original thesis was...

Read more
Next Post
MANTRA co-founder says forced liquidations triggered OM token's 90% crash

MANTRA co-founder says forced liquidations triggered OM token's 90% crash

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 73,471.00
ethereum
Ethereum (ETH) $ 2,011.35
tether
Tether (USDT) $ 0.9986
bnb
BNB (BNB) $ 639.92
xrp
XRP (XRP) $ 1.32
usd-coin
USDC (USDC) $ 0.999593
solana
Solana (SOL) $ 82.18
tron
TRON (TRX) $ 0.353447
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?