cognitive cybersecurity intelligence

News and Analysis

Search

Fake Solana packages target crypto devs, abuse Slack & ImgBB for data theft

Three malicious packages named “solanacore,” “solana-login,” and “walletcore-gen” have been found on the npmjs.com registry targeting Solana crypto developers with Windows malware. Unlike typical crypto-stealer packages, they plainly show their intent to collect keylogging and other sensitive data, rather than attempting to hide their true nature. The packages use Slack web hooks and ImgBB APIs to transfer the collected data to external actors. The packages have been downloaded over 1,900 times.

Source: www.sonatype.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

What AI Can Do for Pharmacist Burnout

Pharmacists are under more strain than ever due to increasing patient demand and administrative tasks, leading to burnout and staff retention issues. The situation is