Several malicious packages have been identified on npm and PyPI that pose as developer tools while stealing cryptocurrency wallet credentials. These include react-native-scrollpageviewtest, web3x, and herewalletbot, with thousands of downloads. They use sophisticated methods to exfiltrate sensitive information through channels like Google Analytics and Telegram bots, highlighting vulnerabilities in the software supply chain.

Hackers Abuse Cloudflare Tunnel Infrastructure to Deliver Multiple RATs
Cybersecurity experts have uncovered a sophisticated attack exploiting Cloudflare’s tunnel infrastructure to distribute remote access trojans (RATs). Phishing emails with disguised attachments initiate the infection,