Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Vulnerability

Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package

September 2, 2025
Reading Time: 2 mins read
Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package

The security of the open-source software ecosystem has been challenged once again by the discovery of a malicious npm package, “nodejs-smtp,” crafted to steal cryptocurrency. Researchers are raising alarms over this sophisticated software supply chain attack, where the package was a deliberate counterfeit of “nodemailer,” one of the most popular emailing libraries in the Node.js ecosystem. By using identical documentation and styling, the malicious package successfully duped developers, leading to hundreds of downloads before it was identified and removed from the public registry. This incident highlights a dangerous trend where threat actors exploit the trust developers place in open-source repositories to distribute malware.

The attack allegedly targeted Windows users with Atomic Wallet or Exodus desktop applications installed. Once a developer included the counterfeit package in a project, it would execute a malicious payload upon installation. This payload was designed to locate the wallet’s application files and inject a “clipper” malware. This type of malware works by monitoring the system’s clipboard for cryptocurrency wallet addresses. When a user copies an address to initiate a transaction, the malware stealthily replaces it with an address belonging to the attacker, effectively hijacking the funds. The scheme reportedly supported a wide range of digital currencies, including Bitcoin (BTC), Ethereum (ETH), Solana (SOL), and Tether (USDT).

What made this attack particularly insidious was its dual functionality. While hiding its malicious code, the “nodejs-smtp” package also operated as a fully functional email tool, mirroring the capabilities of the legitimate “nodemailer.” This allowed it to pass routine application tests and avoid raising suspicion among developers, who would have little reason to suspect a dependency that appeared to be working as intended. This layer of deception demonstrates a deep understanding of developer workflows and represents a significant escalation in the complexity of software supply chain threats, as the malicious code could persist in a compromised application long after the offending package was removed.

Tags: Atomic WalletcryptocurrencyCyberSecurityExodus Walletmalwarenodemailernpmsupply-chain attacktyposquatting
ShareTweet

Related Posts

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware
Vulnerability

CPUID Website Compromised: CPU-Z and HWMonitor Serve Malware

April 10, 2026
Axios npm Package Compromised in Supply Chain Attack
Vulnerability

Axios npm Package Compromised in Supply Chain Attack

March 31, 2026
Critical Figma MCP Server Flaw Allows Remote Code Execution
Vulnerability

Critical Figma MCP Server Flaw Allows Remote Code Execution

October 8, 2025
Oracle Patches CVE−2025−61882
Vulnerability

Oracle Patches CVE−2025−61882

October 6, 2025
Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack
Vulnerability

Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

September 17, 2025
WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000
Vulnerability

WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000

September 8, 2025
Next Post
Threat Actor Allegedly Sells Administrative Access to Crypto Exchange for $5,000

Threat Actor Allegedly Sells Administrative Access to Crypto Exchange for $5,000

Philippine Gaming Regulator PAGCOR Allegedly Breached – Database of Restricted Government Personnel Leaked

Philippine Gaming Regulator PAGCOR Allegedly Breached - Database of Restricted Government Personnel Leaked

Recommended Stories

Zebra Technologies Allegedly Suffers Major Source Code Data Breach

Zebra Technologies Allegedly Suffers Major Source Code Data Breach

January 27, 2026
Alleged Data Breach at NivteIndia.in Exposes Sensitive User Information

Alleged Data Breach at NivteIndia.in Exposes Sensitive User Information

December 15, 2024
Allegations Emerge of a Massive 1.2B Facebook Data Leak on the Dark Web

Allegations Emerge of a Massive 1.2B Facebook Data Leak on the Dark Web

May 20, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?