Breaking
April 16, 2025

Crypto News | Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds Assad Jafri | usagoldmines.com

Researchers have discovered a malicious software package uploaded to npm that secretly alters locally installed versions of crypto wallets and allows attackers to intercept and reroute digital currency transactions, ReversingLabs revealed in a recent report.

The campaign injected trojanized code into locally installed Atomic and Exodus wallet software and hijacked crypto transfers. The attack centered on a deceptive npm package, pdf-to-office, which posed as a library for converting PDF files to Office formats.

When executed, the package silently located and modified specific versions of Atomic and Exodus wallets on victims’ machines, redirecting outgoing crypto transactions to wallets controlled by threat actors.

ReversingLabs said the campaign exemplifies a broader shift in tactics: rather than directly compromising open-source libraries, which often triggers swift community responses, attackers are increasingly distributing packages designed to “patch” local installations of trusted software with stealthy malware.

Targeted file patching

The pdf-to-office package was first uploaded to npm in March and updated multiple times through early April. Despite its stated function, the package lacked actual file conversion features.

Instead, its core script executed obfuscated code that searched for local installations of Atomic Wallet and Exodus Wallet and overwrote key application files with malicious variants.

The attackers replaced legitimate JavaScript files inside the resources/app.asar archive with near-identical trojanized versions that substituted the user’s intended recipient address with a base64-decoded wallet belonging to the attacker.

For Atomic Wallet, versions 2.90.6 and 2.91.5 were specifically targeted. Meanwhile, a similar method was applied to Exodus Wallet versions 25.9.2 and 25.13.3.

Once modified, the infected wallets would continue redirecting funds even if the original npm package was deleted. Full removal and reinstallation of the wallet software were required to eliminate the malicious code.

ReversingLabs also noted the malware’s attempts at persistence and obfuscation. Infected systems sent installation status data to an attacker-controlled IP address (178.156.149.109), and in some cases, zipped logs and trace files from AnyDesk remote access software were exfiltrated, suggesting an interest in deeper system infiltration or evidence removal.

Expanding software supply chain threats

The discovery follows a similar March campaign involving ethers-provider2 and ethers-providerz, which patched the ethers npm package to establish reverse shells. Both incidents highlight the rising complexity of supply chain attacks targeting the crypto space.

ReversingLabs warned that these threats continue to evolve, especially in web3 environments where local installations of open-source packages are common. Attackers increasingly rely on social engineering and indirect infection methods, knowing that most organizations fail to scrutinize already installed dependencies.

According to the report:

“This kind of patching attack remains viable because once the package is installed and the patch is applied, the threat persists even if the source npm module is removed.”

The malicious package was flagged by ReversingLabs’ machine-learning algorithms under Threat Hunting policy TH15502. It has since been removed from npm, but a republished version under the same name and version 1.1.2 briefly reappeared, indicating the threat actor’s persistence.

Investigators published hashes of affected files and wallet addresses used by the attackers as indicators of compromise (IOCs). These include wallets used for illicit fund redirection, as well as the SHA1 fingerprints of all infected package versions and associated trojanized files.

As software supply chain attacks become more frequent and technically refined, especially in the digital asset space, security experts are calling for stricter code auditing, dependency management, and real-time monitoring of local application changes.

The post Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds appeared first on CryptoSlate.

 Researchers have discovered a malicious software package uploaded to npm that secretly alters locally installed versions of crypto wallets and allows attackers to intercept and reroute digital currency transactions, ReversingLabs revealed in a recent report. The campaign injected trojanized code into locally installed Atomic and Exodus wallet software and hijacked crypto transfers. The attack centered
The post Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds appeared first on CryptoSlate. Crypto, Featured, Hacks, Wallets 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

ZKsync Confirms $5M Airdrop Exploit, User Funds Safe Camille Lemmens | usagoldmines.com

Trump onto Xi: US announces 245% tariff on China Florence Muchai | usagoldmines.com

Trump family to launch a crypto real estate game similar to Monopoly Go Collins J. Okoth | usagoldmi...

Jim Cramer intensifies pressure on the Trump administration over deregulation delays Collins J. Okot...

Markets Turn Red as Nvidia Plunges on $5.5B Charge From China Chip Ban Ruholamin Haqshanas | usagold...

Can XRP Defy the Bear Market Again? Price Analysis as Altcoin Inflows Return  Harvey Hunter | usagol...

Why Does This Bitcoin Cycle Feel So Boring? Analyst Weighs In Samuel Edyme | usagoldmines.com

Messari Reports Strong Q1 for TRON with Record Revenue, $19B Daily USDT Volume News Desk | usagoldmi...

Crypto News | S&P 500 futures fall further as Bitcoin lags all major asset classes over last 24 ...

Why is Crypto Market Down Today? Profit-Taking and Recession Fears Hit Prices Nidhi Kolhapur | usago...

Pudgy Penguins Launch Pengu Validator on Solana Victor | usagoldmines.com

This $0.025 Crypto Token Packs More Rally Potential than 2021 Solana (SOL) Cryptopolitan Media | usa...

Russia readies crypto seizure mechanism recognizing coins as property Lubomir Tassev | usagoldmines....

Healthcare Firm Semler Scientific Reports Q1 Paper Losses on Bitcoin Holdings Ruholamin Haqshanas | ...

Bitcoin Drops to $83,000 — China Sells, Meliuz Stacks 45 Coins Arslan Butt | usagoldmines.com

Bitcoin Bulls Positioning Aggressively On Binance, Data Shows Keshav Verma | usagoldmines.com

Crypto News | Why Dogecoin Investors Should Worry About DOGE’s Price Jordan Lyanchev | usagoldmines...

Crypto News | OM Jumps 30% as Mantra CEO Announces Team Token Burn to Rebuild Trust After Crash Way...

PI Token Unlock: 2.8M Tokens Hit the Market Today – Another Pi Coin Price Dip Coming? Vignesh S G | ...

Official Trump (TRUMP) developer pulls $4.6M liquidity, bridges all USDC to Ethereum Hristina Vasile...

Bitcoin Could Face Extended Consolidation Despite Bullish Hype: 10x Research Ruholamin Haqshanas | u...

Crypto News | Ethereum Layer-2 ZKsync Airdrop Account Hacked for $5M Martin Young | usagoldmines.co...

Crypto News | $800M XRP Sell-Off: Are Ripple Whales Signaling a Major Market Shift? Jordan Lyanchev...

Ripple vs. SEC News: Settlement Talks Heat Up, Will XRP Price Finally Break Free? Nidhi Kolhapur | u...

U.S. China Trade War Tensions Rattle Global Markets, Crypto Emerges as Safe Haven Qadir AK | usagold...

XRP ETF Wave Begins: ProShares Leads the Charge, BlackRock Still Silent Zameer Attar | usagoldmines....

Coinbase Alerts Market to Possible Crypto Winter Ahead Shalini Nagarajan | usagoldmines.com

Bitcoin’s Quiet Bull Signal: On-Chain Trends Hint at Another Price Breakout Samuel Edyme | usagoldmi...

Metaplanet Buys Bitcoin Using $10M USD Bonds in Strategic Funding Shift Zafar Naik | usagoldmines.co...

China weighs options for managing seized criminal crypto cache Nellius Irene | usagoldmines.com

Is PEPE About to Explode 100%? Here’s What the Charts Just Revealed Michael Davis | usagoldmines.com

China Grapples With What to Do With Seized Crypto Stash Shalini Nagarajan | usagoldmines.com

SEC Closes Investigation Into NFT Gaming Project CyberKongz Shalini Nagarajan | usagoldmines.com

Bitcoin Undervalued? Analyst Breaks Down Bullish On-Chain Metrics Ash Tiwari | usagoldmines.com

Cardano (ADA) Pressure Mounts—More Downside on the Horizon? Aayush Jindal | usagoldmines.com

Crypto News | Why This Bitcoin (BTC) Rally Isn’t Bringing the Usual Hype Chayanika Deka | usagoldmi...

ETH PRIVACY PUSH IN FOCUS — BUT ROI HUNTERS LOOK TO MAGACOIN FINANCE Cryptopolitan Media | usagoldmi...

Ethereum Price Dips Again—Time to Panic or Opportunity to Buy? Aayush Jindal | usagoldmines.com

XRP Price Pulls Back: Healthy Correction or Start of a Fresh Downtrend? Aayush Jindal | usagoldmines...

Semler Scientific Files for $500 Million Raise to Fuel Bitcoin Investment Strategy Debashree Patra |...

U.S. economy faces billions in losses as foreign tourists stay away Collins J. Okoth | usagoldmines....

TRUMP Coin (TRUMP) Price Analysis: 90% Dip Coming? Joel Frank | usagoldmines.com

Bitcoin Price on The Brink? Signs Point to Renewed Decline Aayush Jindal | usagoldmines.com

‘Bitcoin Wants To Go Higher,’ Says Bitwise CIO—But There’s A Catch Jake Simmons | usagoldmines.com

Ripple CTO issues public warning after suspicious post from John Deaton raises hack concerns Nellius...

Tokyo tech firm Value Creation continues Saylor strategy — Another $700K BTC purchase incoming Graha...

Solana Hits Milestone As Canada OKs First Spot ETFs Christian Encila | usagoldmines.com

Here Are The Top 3 Altcoins Picking Up Where Cardano (ADA) Left Off  Cryptopolitan Media | usagoldmi...

Nvidia faces $5.5 billion blow as U.S. tightens chip export rules to China Nellius Irene | usagoldmi...

XRP CAN’T HIT $20 WITHOUT BREAKING RECORDS — MAGACOIN FINANCE DOESN’T NEED TO Cryptopolitan Media | ...

NASDAQ-listed Japanese Beauty Clinic Operator SBC Completes $418k Bitcoin Purchase Tim Alper | usago...

Bitcoin Price Fails To Launch With $751 Million In Outflows, Are Institutions Cashing Out? Scott Mat...

Crypto News | VanEck proposes Bitcoin-linked Treasury bonds to offset $14 trillion in US debt Gino M...

FTC resolute Meta CEO Zuckerberg bought Instagram to ‘neutralize a competitor’ Enacy Mapakame | usag...

Stock market volatility briefly surpasses Bitcoin amid tariff drama Hannah Collymore | usagoldmines....

Google catches fresh legal probes in Japan Hannah Collymore | usagoldmines.com

Market Structure Legislation Will Boost Bitcoin: Satoshi Act Co-Founder Dennis Jimmy Aki | usagoldmi...

SOL Strategies and Pudgy Penguins Launch PENGU Validator on Solana Network Hassan Shittu | usagoldmi...

New Poll Shows Americans Believe Tech Companies, Elon Musk Has Too Much Power Over Government Julia ...

British Man Apprehended At Airport, Jailed for More Than 8 Years Over Phishing Scam Julia Smith | us...

Cardano (ADA) Chart Setup Hints At A Major Upside Ahead – Here’s Why Godspower Owie | usagoldmines.c...

Crypto News | Corporate BTC Buying Surged in Q1 Despite Market Correction Martin Young | usagoldmin...

Crypto News | OFAC keeps developers in the crosshairs despite Tornado Cash delisting Gino Matos | us...

SEC resists DOGE’s request for deep access to internal data Noor Bazmi | usagoldmines.com

Trump wants China to propose a tarriff deal and end the conflict Shummas Humayun | usagoldmines.com

J&J prepares for $400M in tariff costs amid strong earnings Noor Bazmi | usagoldmines.com

Chamath Palihapitiya breaks down Trump’s reciprocal tariffs Randa Moses | usagoldmines.com

Renowned Trader Explains Why This Token Deserves a Spot in Your 2025 Portfolio, Even More Than Carda...

Tether Invests in Fizen to Advance Stablecoin Adoption Tanzeel Akhtar | usagoldmines.com

Crypto News | Mantra CEO vows token burn to regain investor trust after OM collapse Gino Matos | usa...

XRP BACK ON CMC TRENDING — WHILE MAGACOIN FINANCE SOLD OUT 6 STAGE Cryptopolitan Media | usagoldmine...

Warren Buffett holds enough cash to buy 476 companies in the S&P 500 at current values Jai Hamid...

Over 18 million US crypto user records surface on dark web in major data breach Cryptopolitan News |...

$10 XRP Rocket Envisioned Amid High Likelihood Of Ripple’s Coin Winning Spot ETF Approval Before DOG...

Trump Family to Launch Blockchain Real Estate Game Inspired by MONOPOLY GO! Hassan Shittu | usagoldm...

Phantom Faces Lawsuit over Security Vulnerabilities in Crypto Wallet Jimmy Aki | usagoldmines.com

Ethereum Metrics Reveal Critical Support Level – Can Buyers Step In? Sebastian Villafuerte | usagold...

Crypto News | White House Mulls Bitcoin Reserve Backed by Gold and Tariffs Wayne Jones | usagoldmin...

Crypto News | Nigerian investors blindsided by massive CBEX Ponzi scheme Oluwapelumi Adejumo | usago...

Crypto News | Trump reportedly developing Monopoly-inspired crypto game Gino Matos | usagoldmines.co...

Cardano (ADA), Ripple (XRP), Mutuum Finance (MUTM): Watch These Altcoins As We Begin Q2 2025 Cryptop...

NATO closes AI military system deal Palantir, US software company chaired by Donald Trump-backer Pet...

Sam Altman’s OpenAI is building a Musk X-like social network Florence Muchai | usagoldmines.com

Binance Whales Unfazed, Bitcoin Inflows Plummet $3 Billion Aliyu Pokima | usagoldmines.com

Veteran Trader Peter Brandt Slams Ethereum, Brands It ‘Worthless Junk’ Brenda Ngari | usagoldmines.c...

White House Hints Tariff Revenue May Help Build US Strategic Bitcoin Reserve Brenda Ngari | usagoldm...

Swedish Lawmakers Urge Finance Minister to Explore National Bitcoin Reserve Hassan Shittu | usagoldm...

Dogecoin Price To Enter Phase E After Testing Last Point Of Support, Here’s The Target Scott Mathers...

Crypto News | Top Cardano (ADA) Price Predictions as of Late Dimitar Dzhondzhorov | usagoldmines.co...

Crypto News | SEC concludes review of Coinbase disclosures after over 2 years, no amendments require...

Mutuum Finance (MUTM) Token Price’s Road to $5: Why You Should Anticipate a Powerful Rise in April 2...

Trump goes after Harvard’s tax-exempt status as standoff escalates Florence Muchai | usagoldmines.co...

Swedish MP pushes for national Bitcoin reserve as U.S. and EU debate strategic adoption Nellius Iren...

Crypto News | ZKsync admin wallet compromised in $5 million theft, ZK slides over 8% Gino Matos | us...

Crypto News | Kripton selects TRON and Tether to Drive Cryptocurrency Adoption and Financial Inclusi...

Mutuum Finance (MUTM) on Track for 11,300% Return, Outshining Major Cryptos in 2025 Cryptopolitan Me...

Market Watch: Mantra Slides 85%, Solana Maintains $130 Support, XYZVerse Gains Bullish Momentum Cryp...

Best crypto exchanges for US residents: How to choose the best Alden Baldwin | usagoldmines.com

Trump’s tariffs will destroy U.S. economy, former Treasury secretary predicts Noor Bazmi | usagoldmi...

New Phishing Scheme Targets Crypto Futures On MEXC Exchange Sead Fadilpašić | usagoldmines.com

Leave a Reply