- Популярные видео
- Авто
- Видео-блоги
- ДТП, аварии
- Для маленьких
- Еда, напитки
- Животные
- Закон и право
- Знаменитости
- Игры
- Искусство
- Комедии
- Красота, мода
- Кулинария, рецепты
- Люди
- Мото
- Музыка
- Мультфильмы
- Наука, технологии
- Новости
- Образование
- Политика
- Праздники
- Приколы
- Природа
- Происшествия
- Путешествия
- Развлечения
- Ржач
- Семья
- Сериалы
- Спорт
- Стиль жизни
- ТВ передачи
- Танцы
- Технологии
- Товары
- Ужасы
- Фильмы
- Шоу-бизнес
- Юмор
Crypto-Stealing Code Found in npm & PyPI Packages
ALERT: Malicious open-source packages targeting crypto wallets have been uncovered on npm and PyPI, downloaded thousands of times by unsuspecting developers. The packages silently steal mnemonic seed phrases and private keys—and some are still active.
Malicious Packages Identified:
react-native-scrollpageviewtest (npm): 1,215 downloads
Exfiltrates wallet secrets via Google Analytics
Obfuscated & dynamic loader of React Native wallet engine
web3x (PyPI): 3,405 downloads
Poses as Ethereum balance checker
Steals seed phrases via Telegram bot
herewalletbot (PyPI): 3,425 downloads
Uses Telegram chat interface to harvest seed phrases
Exfiltration Emails / Endpoints:
twoplusten@163[.]com
xeallmail@mitico[.]org
bevansatria@gmail[.]com
hxxps://web[.]telegram[.]org/k/#@herewalletbot
These tools blend into dev workflows, making them hard to detect—highlighting the rising threat of software supply chain attacks.
Dev Security Tips:
NEVER share your mnemonic or private keys
Review code before installing unknown packages
Monitor runtime behavior & audit dependencies
Flag and report any package requesting sensitive wallet data
#CryptoSecurity #OpenSource #PyPI #npm #MalwareAlert #SupplyChainAttack #SeedPhraseTheft #Web3Security #DevSecOps #CyberSecurityNews
Видео Crypto-Stealing Code Found in npm & PyPI Packages канала Secure Thread
Malicious Packages Identified:
react-native-scrollpageviewtest (npm): 1,215 downloads
Exfiltrates wallet secrets via Google Analytics
Obfuscated & dynamic loader of React Native wallet engine
web3x (PyPI): 3,405 downloads
Poses as Ethereum balance checker
Steals seed phrases via Telegram bot
herewalletbot (PyPI): 3,425 downloads
Uses Telegram chat interface to harvest seed phrases
Exfiltration Emails / Endpoints:
twoplusten@163[.]com
xeallmail@mitico[.]org
bevansatria@gmail[.]com
hxxps://web[.]telegram[.]org/k/#@herewalletbot
These tools blend into dev workflows, making them hard to detect—highlighting the rising threat of software supply chain attacks.
Dev Security Tips:
NEVER share your mnemonic or private keys
Review code before installing unknown packages
Monitor runtime behavior & audit dependencies
Flag and report any package requesting sensitive wallet data
#CryptoSecurity #OpenSource #PyPI #npm #MalwareAlert #SupplyChainAttack #SeedPhraseTheft #Web3Security #DevSecOps #CyberSecurityNews
Видео Crypto-Stealing Code Found in npm & PyPI Packages канала Secure Thread
Комментарии отсутствуют
Информация о видео
23 апреля 2025 г. 22:30:02
00:00:11
Другие видео канала





















