5 Malicious npm Packages Typosquat Solana and Ethereum Libra...
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Socket's Threat Research Team discovered five malicious npm packages published under the account galedonovan that typosquat legitimate Solana and Ethereum crypto libraries. Each package intercepts private key operations at runtime — Base58 decode() calls for Solana and the Wallet constructor for Ethereum — and silently
Table of contents
The Theft Mechanism #C2 Infrastructure #Per-Package Breakdown #Attribution Links Across the Five Packages #Outlook and Recommendations #MITRE ATT&CK #Indicators of Compromise (IOCs) #Sort: