• bitcoinBitcoin (BTC) $ 78,502.00
  • ethereumEthereum (ETH) $ 2,395.25
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.44
  • bnbBNB (BNB) $ 639.74
  • usd-coinUSDC (USDC) $ 0.999788
  • solanaSolana (SOL) $ 87.30
  • tronTRON (TRX) $ 0.330005
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.096256
  • whitebitWhiteBIT Coin (WBT) $ 55.92
  • usdsUSDS (USDS) $ 0.999706
  • hyperliquidHyperliquid (HYPE) $ 41.34
  • leo-tokenLEO Token (LEO) $ 10.27
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • bitcoin-cashBitcoin Cash (BCH) $ 462.22
  • cardanoCardano (ADA) $ 0.250151
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 373.42
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.36
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • stellarStellar (XLM) $ 0.177203
  • canton-networkCanton (CC) $ 0.152335
  • memecoreMemeCore (M) $ 4.41
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • zcashZcash (ZEC) $ 318.77
  • daiDai (DAI) $ 0.999665
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.999464
  • litecoinLitecoin (LTC) $ 55.83
  • usd1-wlfiUSD1 (USD1) $ 0.999934
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • avalanche-2Avalanche (AVAX) $ 9.41
  • hedera-hashgraphHedera (HBAR) $ 0.091120
  • suiSui (SUI) $ 0.952328
  • wethWETH (WETH) $ 2,268.37
  • rainRain (RAIN) $ 0.007753
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • paypal-usdPayPal USD (PYUSD) $ 0.999797
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.37
  • crypto-com-chainCronos (CRO) $ 0.070037
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,710.66
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.078614
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 247.29
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • global-dollarGlobal Dollar (USDG) $ 0.999735
  • pax-goldPAX Gold (PAXG) $ 4,714.47
  • polkadotPolkadot (DOT) $ 1.27
  • mantleMantle (MNT) $ 0.646894
  • uniswapUniswap (UNI) $ 3.34
  • skySky (SKY) $ 0.083245
  • nearNEAR Protocol (NEAR) $ 1.41
  • falcon-financeFalcon USD (USDF) $ 0.997106
  • okbOKB (OKB) $ 84.24
  • pi-networkPi Network (PI) $ 0.168726
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.675668
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ripple-usdRipple USD (RLUSD) $ 0.999958
  • aaveAave (AAVE) $ 94.32
  • internet-computerInternet Computer (ICP) $ 2.51
  • usddUSDD (USDD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 1.94
  • ethereum-classicEthereum Classic (ETC) $ 8.53
  • bfusdBFUSD (BFUSD) $ 0.999994
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ondo-financeOndo (ONDO) $ 0.262683
  • kucoin-sharesKuCoin (KCS) $ 8.54
  • gatechain-tokenGate (GT) $ 7.41
  • pump-funPump.fun (PUMP) $ 0.001855
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • morphoMorpho (MORPHO) $ 1.97
  • quant-networkQuant (QNT) $ 73.58
  • united-stablesUnited Stables (U) $ 0.999783
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.093435
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • render-tokenRender (RENDER) $ 1.82
  • ethenaEthena (ENA) $ 0.107628
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • cosmosCosmos Hub (ATOM) $ 1.87
  • kaspaKaspa (KAS) $ 0.034398
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • algorandAlgorand (ALGO) $ 0.103293
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.913040
  • usdtbUSDtb (USDTB) $ 0.999747
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • worldcoin-wldWorldcoin (WLD) $ 0.265684
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • wbnbWrapped BNB (WBNB) $ 759.61
  • arbitrumArbitrum (ARB) $ 0.130383
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.953919
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • filecoinFilecoin (FIL) $ 0.935436
  • justJUST (JST) $ 0.082469
  • flare-networksFlare (FLR) $ 0.008026
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • official-trumpOfficial Trump (TRUMP) $ 2.93
  • midnight-3Midnight (NIGHT) $ 0.037423
  • vechainVeChain (VET) $ 0.007192
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • jupiter-exchange-solanaJupiter (JUP) $ 0.173746
  • beldexBeldex (BDX) $ 0.079721
  • ousgOUSG (OUSG) $ 115.01
  • xdce-crowd-saleXDC Network (XDC) $ 0.029893
  • hash-2Provenance Blockchain (HASH) $ 0.010234
  • yldsYLDS (YLDS) $ 0.999776
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 0.998903
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • stable-2​​Stable (STABLE) $ 0.026284
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • dexeDeXe (DEXE) $ 12.14
  • bonkBonk (BONK) $ 0.000006
  • usual-usdUsual USD (USD0) $ 0.998071
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.008309
  • edgexedgeX (EDGE) $ 1.43
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.52
  • true-usdTrueUSD (TUSD) $ 0.998323
  • chilizChiliz (CHZ) $ 0.047300
  • a7a5A7A5 (A7A5) $ 0.012382
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.208850
  • siren-2Siren (SIREN) $ 0.637712
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.698774
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 35.52
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • adi-tokenADI (ADI) $ 4.29
  • euro-coinEURC (EURC) $ 1.17
  • blockstackStacks (STX) $ 0.227750
  • sei-networkSei (SEI) $ 0.061375
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999308
  • venice-tokenVenice Token (VVV) $ 8.92
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • tezosTezos (XTZ) $ 0.374697
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • monadMonad (MON) $ 0.033842
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • aerodrome-financeAerodrome Finance (AERO) $ 0.429233
  • layerzeroLayerZero (ZRO) $ 1.57
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • ether-fiEther.fi (ETHFI) $ 0.459605
  • usxUSX (USX) $ 0.999377
  • spx6900SPX6900 (SPX) $ 0.395302
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • sun-tokenSun Token (SUN) $ 0.018784
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • kinesis-goldKinesis Gold (KAU) $ 151.24
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.358669
  • decredDecred (DCR) $ 20.22
  • curve-dao-tokenCurve DAO (CRV) $ 0.228564
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • hastra-primePRIME (PRIME) $ 1.03
  • celestiaCelestia (TIA) $ 0.371034
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • apenftAINFT (NFT) $ 0.00000034
  • injective-protocolInjective (INJ) $ 3.30
  • gnosisGnosis (GNO) $ 123.93
  • lido-daoLido DAO (LDO) $ 0.382926
  • bitcoin-svBitcoin SV (BSV) $ 16.06
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • flokiFLOKI (FLOKI) $ 0.000033
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • conflux-tokenConflux (CFX) $ 0.059326
  • kinesis-silverKinesis Silver (KAG) $ 77.85
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • doublezeroDoubleZero (2Z) $ 0.083913
  • jasmycoinJasmyCoin (JASMY) $ 0.005742
  • kaiaKaia (KAIA) $ 0.048145
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • usdaiUSDai (USDAI) $ 0.999646
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • zebec-networkZebec Network (ZBCN) $ 0.002859
  • fraxLegacy Frax Dollar (FRAX) $ 0.993252
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • kite-2Kite (KITE) $ 0.150916
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Hacker targets ETH and SOL devs via typosquat npm packages

0 18

Hacker targets ETH and SOL devs via typosquat npm packages

Ethereum and Solana developers were targeted by five malicious npm packages that steal private keys and send them to the attacker. The packages rely on typosquatting, mimicking legitimate crypto libraries.

Security researchers from Socket found the five malicious npm packages published under a single account. The malicious campaign covers the Ethereum and Solana ecosystems, with active command and control (C2) infrastructure.

One of the packages was unpublished within five minutes, but it hid its code and sent stolen data to the attacker.

Hackers target Ethereum and Solana devs

Crypto hackers do not only target retail investors and the elderly. They rely on social engineering tactics and typosquatting to trick developers and steal their crypto.

Typosquatting is a tactic where attackers create fake packages with names similar to popular libraries. Developers may accidentally install these malicious packages, thinking they are legitimate.

The job of the malicious packages is to divert keys to a hardcoded Telegram bot.

The malicious npm attack works by hooking functions that developers use to pass private keys. When a function is called, the package sends the key to the attacker’s Telegram bot before returning the expected result. This makes the attack invisible to the unaware devs.

According to security researchers, four packages target Solana developers, while one targets Ethereum developers.

Hacker targets ETH and SOL devs via typosquat npm packages

Malicious npm packages vs. legitimate crypto libraries. Source: Socket.

The four packages targeting Solana intercept Base58 decode() calls, while the ethersproject-wallet package targets the Ethereum Wallet constructor.

All of the malicious packages rely on global fetch, which requires Node.js 18 or later. On older versions, the request fails silently, and no data is stolen.

All packages send data to the same Telegram endpoint. The bot token and chat ID are hardcoded in every package, and there is no external server, so the channel works as long as the Telegram bot stays online.

The raydium-bs58 package is the simplest. It modifies a decode function and sends the key before returning the result. The README is copied from a legitimate SDK, and the author field is empty.

The second Solana package, base-x-64, hides the payload with obfuscation. The payload sends a message to Telegram with the stolen key.

The bs58-basic package contains no malicious code itself but it depends on base-x-64 and passes the payload through the chain.

The Ethereum package, ethersproject-wallet package, copies a real library, @ethersproject/wallet. The malicious package inserts one extra line after compilation. The change appears only in the compiled file, which confirms manual tampering.

All packages share the same command endpoint, typos, and build artifacts. Two packages use identical compiled files. Another package depends directly on the other. These links point to a single actor using the same workflow.

Takedown requests have been submitted to npm by security researchers. Private keys lost to this attack are compromised and any associated funds should be moved quickly to a new wallet.

Hackers continue to target crypto devs. According to Cryptopolitan, hackers managed to infect 178 macOS devs through a fake OpenClaw installer. The fake installer, dubbed GhostClaw was listed on the npm registry for a while before being removed. It was designed to steal private keys, seed phrases, and other sensitive data.

Source

Leave A Reply

Your email address will not be published.