cognitive cybersecurity intelligence

News and Analysis

Search

Malicious npm and PyPI Pose as Developer Tools to Steal Login Credentials

Malicious npm and PyPI Pose as Developer Tools to Steal Login Credentials

Several malicious packages have been identified on npm and PyPI that pose as developer tools while stealing cryptocurrency wallet credentials. These include react-native-scrollpageviewtest, web3x, and herewalletbot, with thousands of downloads. They use sophisticated methods to exfiltrate sensitive information through channels like Google Analytics and Telegram bots, highlighting vulnerabilities in the software supply chain.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts