Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

9-Year-Old NPM Crypto Package Hijacked for Information Theft

Nearly a dozen crypto packages on NPM, including one published 9 years ago, have been hijacked to deliver infostealers.

Multiple NPM packages designed for blockchain application development have been hijacked to deliver information stealer malware, software supply chain management firm Sonatype reports.

The packages provide legitimate functionality for developers building applications that interact with blockchain services, but their latest versions contain obfuscated scripts, being able to steal sensitive information from the victims’ systems.

With a total combined download count of roughly 500,000 over their entire lifetimes, these packages have been available in the NPM registry for years, one for nearly a decade.

The malicious updates, however, were published recently, with the changes observed only on NPM, while the GitHub repositories remained untouched, Sonatype says.

At least two of the hijacked packages, namely ‘bnb-javascript-sdk-nobroadcast’ and ‘country-currency-map’ have not had new versions published for years, but new releases containing malicious code popped up on NPM for both this week.

The malicious version of ‘country-currency-map’ was deprecated shortly after it was published, with the maintainers recommending the use of the previous version, published five years ago.

Advertisement. Scroll to continue reading.

In both packages, Sonatype identified highly obfuscated scripts that run during installation, and which collect sensitive information such as system environment variables, which could store access tokens, API keys, SSH credentials, and other data.

Malicious versions of ‘@bithighlander/bitcoin-cash-js-lib’, ‘eslint-config-travix’, ‘@crosswise-finance1/sdk-v2’, ‘@keepkey/device-protocol’, ‘@veniceswap/uikit’, ‘@veniceswap/eslint-config-pancake’, ‘babel-preset-travix’, ‘@travix/ui-themes’, and ‘@coinmasters/types’ were also identified.

The hijacks, the company notes, may have been performed after old maintainer accounts were compromised, likely via credential stuffing.

“Although NPM mandated two-factor authentication (2FA) for high impact projects in 2022 (e.g. authors of NPM packages receiving 1 million weekly downloads or with more than 500 dependents), some authors still need to enroll in two-factor authentication,” Sonatype notes.

Related: Developers Targeted With Malware Disguised as DeepSeek Package

Related: Snyk Says ‘Malicious’ NPM Packages Part of Research Project

Related: Open Source Package Entry Points May Lead to Supply Chain Attacks

Related: Cryptocurrency Wallets Targeted via Python Packages Uploaded to PyPI

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.