Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

A new set of four malicious packages have been discovered in the npm package registry with capabilities to steal cryptocurrency wallet credentials from Ethereum developers.
“The packages masquerade as legitimate cryptographic utilities and Flashbots MEV infrastructure while secretly exfiltrating private keys and mnemonic seeds to a Telegram bot controlled by the threat actor,” Socket researcher

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation

Next Post

Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign

Related Posts
Total
0
Share