Thursday, December 25, 2025
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Cryptocurrency

Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets

cryptonews100_tggfrn by cryptonews100_tggfrn
September 2, 2025
in Cryptocurrency
0
Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


Sep 02, 2025Ravie LakshmananCryptocurrency / Malware

Cybersecurity researchers have found a malicious npm package deal that comes with stealthy options to inject malicious code into desktop apps for cryptocurrency wallets like Atomic and Exodus on Home windows methods.

The package deal, named nodejs-smtp, impersonates the legit electronic mail library nodemailer with an an identical tagline, web page styling, and README descriptions, attracting a complete of 347 downloads because it was uploaded to the npm registry in April 2025 by a consumer named “nikotimon.” It is at present not out there.

“On import, the package deal makes use of Electron tooling to unpack Atomic Pockets’s app.asar, substitute a vendor bundle with a malicious payload, repackage the appliance, and take away traces by deleting its working listing,” Socket researcher Kirill Boychenko said.

CIS Build Kits

The principle goal is to overwrite the recipient deal with with hard-coded wallets managed by the risk actor, redirecting Bitcoin (BTC), Ethereum (ETH), Tether (USDT and TRX USDT), XRP (XRP), and Solana (SOL) transactions, successfully appearing as a cryptocurrency clipper.

That having stated, the package deal delivers on its said performance by appearing as an SMTP-based mailer in an try and keep away from elevating builders’ suspicion.

The package deal nonetheless works as a mailer and exposes a drop-in interface suitable with nodemailer. That practical cowl lowers suspicion, permits utility assessments to go, and offers builders little cause to query the dependency.

The event comes months after ReversingLabs discovered an npm package deal named “pdf-to-office” that achieved the identical objectives by unpacking the “app.asar” archives related to Atomic and Exodus wallets and modifying inside them a JavaScript file to introduce the clipper perform.

“This marketing campaign reveals how a routine import on a developer workstation can quietly modify a separate desktop utility and persist throughout reboots,” Boychenko stated. “By abusing import time execution and Electron packaging, a lookalike mailer turns into a pockets drainer that alters Atomic and Exodus on compromised Home windows methods.”



Source link

Related articles

Eun Young Choi Discusses North Korean Cryptocurrency Theft in Yahoo Finance | Media Mentions

Eun Young Choi Discusses North Korean Cryptocurrency Theft in Yahoo Finance | Media Mentions

December 24, 2025
Cryptocurrency marketplace publishes up-to-date data

Cryptocurrency marketplace publishes up-to-date data

December 24, 2025
Tags: AtomicexodusmaliciousmimicsnodejssmtpNodemailernpmPackagetargetswallets
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

Eun Young Choi Discusses North Korean Cryptocurrency Theft in Yahoo Finance | Media Mentions

Eun Young Choi Discusses North Korean Cryptocurrency Theft in Yahoo Finance | Media Mentions

by cryptonews100_tggfrn
December 24, 2025
0

Eun Young Choi, Arnold & Porter White Collar Protection & Investigations associate and former Deputy Assistant Lawyer Normal in the...

Cryptocurrency marketplace publishes up-to-date data

Cryptocurrency marketplace publishes up-to-date data

by cryptonews100_tggfrn
December 24, 2025
0

Economic system Supplies 24 December 2025 20:57 (UTC +04:00) The newest cryptocurrency market data reveals combined weekly efficiency,...

Federal Reserve Interest Rate Decisions Inflicting Change on Cryptocurrency Markets

Federal Reserve Interest Rate Decisions Inflicting Change on Cryptocurrency Markets

by cryptonews100_tggfrn
December 24, 2025
0

Right here we stand on the sting of January 2026, with bated breath, poised for the Federal Reserve's impending choices...

SEC Says Cryptocurrency Scam Took $14M From Retail Investors

SEC Says Cryptocurrency Scam Took $14M From Retail Investors

by cryptonews100_tggfrn
December 24, 2025
0

An funding rip-off allegedly took $14 million from retail traders by connecting with them on social media and convincing them...

Record $2.7 Billion Cryptocurrency Theft in 2025 Driven by North Korean Hackers | Ukraine news

Record $2.7 Billion Cryptocurrency Theft in 2025 Driven by North Korean Hackers | Ukraine news

by cryptonews100_tggfrn
December 23, 2025
0

In 2025, hackers and different cybercriminals seized about $2.7 billion in cryptocurrency – a document excessive in the historical past...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

VanEck Manager Predicts Strong Bitcoin Comeback in 2026 Despite Its Current ‘Lag’

December 25, 2025
NBCOIN Announces Launch of Its RWA Connector and

NBCOIN Announces Launch of Its RWA Connector and

December 25, 2025
Metaplanet’s financial gymnastics paves way for potential Bitcoin buy

Metaplanet’s financial gymnastics paves way for potential Bitcoin buy

December 25, 2025

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Exchanges
  • Pokadot
  • Polygon
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (221) Altcoins (140) Bitcoin (1014) BTC (250) Buy (357) Cardano (450) ChainLink (334) crypto (1305) Cryptocurrency (420) DOGE (190) Dogecoin (455) DOT (155) ETF (283) ETFs (145) ETH (265) Ethereum (625) eyes (146) Heres (149) Inu (331) investors (159) Launch (148) launches (154) Link (147) market (416) million (162) News (532) Polkadot (243) POLYGON (196) prediction (332) Presale (225) price (973) rally (211) RWA (203) SHIB (154) Shiba (342) Solana (538) Stablecoin (147) Sui (334) support (141) today (148) token (162) top (280) TradingView (186) Trump (181) XRP (761)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Litecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.