FortiGuard Labs has identified malicious NPM packages targeting developers and PayPal users, published by the alias “tommyboy_h1” and “tommyboy_h2.” These packages exploit PayPal’s brand to deceive users, deploying scripts that collect sensitive system data. Many packages were released quickly, raising concerns for small to medium businesses. Users are advised to verify NPM packages and enhance security measures.

Hackers are Targeting Atomic and Exodus Wallets
Cybercriminals are targeting users of Atomic and Exodus wallets through malware hidden in open-source software repositories. The malicious code attempts to compromise private keys and