headphones
Cybercriminals Hijacking Popular Crypto Software To Steal Digital Assets From Wallets: Security Researchers
链上信仰者
链上信仰者
authIcon
区块链先知
04-15 03:01
Follow
Focus
Security researchers are warning that threat actors are using less noticeable techniques to compromise and steal funds from crypto wallets.
Helpful
Not Helpful
Play

Security researchers are warning that threat actors are using less noticeable techniques to compromise and steal funds from crypto wallets.

Cybersecurity firm ReversingLabs says that cybercriminals are now uploading malicious packages to popular open-source software repositories such as the npm (Node Package Manager).

The objective is to inject malicious code into trusted local libraries without raising suspicion. 

According to ReversingLabs, its research team has identified a new malware campaign targeting crypto users that uses what appears to be a legitimate npm package for converting PDF format files into Microsoft Office documents. 

When executed, the pdf-to-office npm package will inject malicious code into locally-installed Atomic and Exodus crypto wallets and overwrite their existing, non-malicious files to switch the address for outgoing crypto funds. When a compromised user attempts to send crypto assets to another wallet, the funds will be sent to one controlled by the malicious actors.

ReversingLabs says removing the package will not be enough to terminate the malicious activities. 

“The Web3 wallets’ software would remain compromised and continue to channel crypto funds to the attackers’ wallet. The only way to completely remove the malicious trojanized files from the Web3 wallets’ software would be to remove them completely from the computer and re-install them.”

Follow us on X, Facebook and Telegram

Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix


Generated Image: Midjourney

Open the app to read the full article
DisclaimerAll content on this website, hyperlinks, related applications, forums, blog media accounts, and other platforms published by users are sourced from third-party platforms and platform users. BiJieWang makes no warranties of any kind regarding the website and its content. All blockchain-related data and other content on the website are for user learning and research purposes only, and do not constitute investment, legal, or any other professional advice. Any content published by BiJieWang users or other third-party platforms is the sole responsibility of the individual, and has nothing to do with BiJieWang. BiJieWang is not responsible for any losses arising from the use of information on this website. You should use the related data and content with caution and bear all risks associated with it. We strongly recommend that you independently research, review, analyze, and verify the content.
Comments(0)

No comments yet

edit
comment
collection
like
share