Breaking
April 18, 2025

New Malicious Campaign Targets Atomic and Exodus Wallets Sead Fadilpašić | usagoldmines.com

The security firm ReversingLabs’ research team has discovered yet another campaign targeting specific versions of the popular crypto wallets Exodus and Atomic.

According to the report, threat actors “have been targeting the cryptocurrency community hard lately.” They’re using various methods to hijack popular and legitimate crypto packages to loot people’s wallets.

However, the researchers highlight that hijacking open-source packages is difficult due to the size of the open-source software (OSS) developer community. The tampered-with OSS packages will be detected.

Therefore, threat actors are working hard to make their methods more obscure. A new technique that ReversingLabs discovered is uploading packages to OSS repositories and having them apply malicious ‘patches’ to local versions of legitimate libraries.

The goal is the same: install an unnoticeable malicious code in a popular, trusted local library.

The researchers found “a number of campaigns” in recent weeks attempting this strategy. Notably, on 1 April, a malicious entity published a package, pdf-to-office, to the npm package manager. This package posed as a library for converting PDF to Microsoft Office documents.

Once executed, it would inject malicious code into locally installed Atomic Wallet and Exodus. It would overwrite existing files. “Effectively, a victim who tried to send crypto funds to another wallet would have the intended destination address swapped out for one belonging to the malicious actor,” the report states.

List of TH policies in package pdf-to-office@1.0.2. Source: ReversingLabs

Additionally, this campaign is quite similar to the one the researchers discussed in a research post in March.

In both of these cases, the malicious campaign had no effect on the official Atomic Wallet and Exodus Wallet installers available on the websites.

Aiming for Specific Wallet Versions

ReversingLabs first detected the pdf-to-office package after its update to npm on 1 April. It was removed soon after detection. But a couple of days later, the threat actor published a new version that looked like the first one. They released three versions of the package over a few weeks in March and April with the same functionality.

The malicious payload worked to detect the presence of the atomic/resources/app.asar archive inside AppData/Local/Programs directory. Finding it would mean that the unsuspecting user installed Atomic Wallet on their now-infected computer.

Then, the malicious code searched for the archive to overwrite one of its files with a trojanized version that changes the outgoing crypto address. Now, the funds would go straight to the threat actor’s wallet.

“That was the only difference between the legitimate and trojanized file, except that the malicious version of the file was not minified,” the report notes.

The difference between a legitimate and trojanized file. Source: ReversingLabs

Additionally, the threat actors focused on specific versions of Atomic. The attack code would adjust which files were overwritten based on the wallet version it found.

Moreover, there was a malicious payload that attempted to inject a trojanized file inside a legitimate, locally-installed Exodus wallet. It targeted the two latest versions of Exodus.

Also, if the victim removed the package pdf-to-office from the computer, the Web3 wallets’ software would still remain compromised. This means it would continue directing crypto to the attackers’ wallet.

“The only way to completely remove the malicious trojanized files from the Web3 wallets’ software would be to remove them completely from the computer and re-install them,” ReversingLabs concludes.

Meanwhile, North Korea’s Lazarus group has been targeting crypto developers via npm supply chain attacks for months in a highly sophisticated global campaign to steal funds and data.

The post New Malicious Campaign Targets Atomic and Exodus Wallets appeared first on Cryptonews.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Crypto News | Canary files for staked TRX ETF amid ongoing staking discussions in the US Gino Matos ...

Shiba Inu (SHIB) Barks Again as Bulls Return, But Is Mutuum Finance (MUTM) the Real 100x Gem in 2025...

Investing In Solana (SOL) and Cardano (ADA) Can’t Bring Any Life Changing Gains Soon; Investors Eye ...

Retail investors keep buying the dip but what happens when the market doesn’t bounce back? Noor Bazm...

Weekly Crypto Regulation News Roundup: SEC Sets Roundtable, Russia Eyes Stablecoins, and Canada Appr...

Bitcoin Enters Oversold Levels, Analyst Warns This Is Bearish, Not Bullish Scott Matherson | usagold...

Crypto News | eXch Collapse: Accused of Laundering Crypto for Bybit Hackers, Platform Bows Out Chay...

Crypto News | Kyrgyzstan moves toward digital currency with new CBDC legislation Assad Jafri | usago...

Binance Helps Countries Plan Bitcoin Reserves Lawrence Mike Woriji | usagoldmines.com

Bybit Backs Vietnam’s Crypto Trading Pilot with Tech and Risk Support Hassan Shittu | usagoldmines.c...

‘Bitcoin Is Calling’ – Saylor Stirs The Market With Cryptic Clue Christian Encila | usagoldmines.com

Crypto News | Can Quantum Computing Break Bitcoin? Project Eleven Puts It to the Test Chayanika Dek...

Crypto News | Ethereum’s planned blob increases insufficient to sustain L2 transaction growth Gino M...

Dogecoin (DOGE) and Shiba Inu (SHIB) Lose The Fight Versus Utility Tokens; Investors Shift Their Att...

Investing $500 in This Cardano (ADA) Competitor Under $0.05 Could Yield $50,000 Before ADA Price Hit...

Corporate Bitcoin Holdings Hit 668K BTC In Q1 2025, Mass Adoption Incoming? Aliyu Pokima | usagoldmi...

President Trump’s Crypto Advisor Reveals Ways To Bolster Bitcoin Reserves Aliyu Pokima | usagoldmine...

Bitcoin OG Foresees Ripple’s XRP Doing Something Crazy And Reaching $24 This Year — But There’s A Ca...

$1.4B in Bitcoin Sold by Chinese Authorities Amid Lack of Oversight Newton Gitonga | usagoldmines.co...

Are the Good Days Coming For Ethereum after Reclaiming $1,600? Brian Njuguna | usagoldmines.com

Addresses Holding More Than 1 XRP Reach Historic Highs Despite Volatility Going Through the Roof Bri...

Crypto News | Coinbase and traditional financial firms poised to benefit from US stablecoin legislat...

Mutuum Finance (MUTM): The Game-Changer in DeFi Lending And Borrowing Cryptopolitan Media | usagoldm...

MoonPay CEO’s Letter to Congress: Stablecoin Bill Risks Creating National Monopoly Tanzeel Akhtar | ...

Solana Price Enters Consolidation Trend Above $130 That Could End In A Breakout Scott Matherson | us...

Crypto News | Current Bitcoin (BTC) Correction Fits Historical Mid-Cycle Reset Pattern Perfectly: B...

Crypto News | Coinbase sounds alarm against potential Oregon ‘copycat’ securities lawsuit Oluwapelum...

Expert Advice: Do Not Sell Ethereum (ETH) Too Soon, And Buy More of This Coin Priced At $0.025 Crypt...

CZ-consulting Kyrgyz Republic greenlights pilot CBDC program, assigns legal status Hannah Collymore ...

Coinbase Faces Déjà Vu: Oregon AG ‘Revives’ SEC Allegations in High‑Stakes State Suit Hassan Shittu ...

BONK Symmetrical Triangle Squeeze: Is A Mega Breakout Imminent? Godspower Owie | usagoldmines.com

Crypto News | Bitcoin’s Market Dominance Skyrockets Amid Global Economic Uncertainty: Your Weekly C...

Crypto News | Arizona edges closer to crypto treasury, but governor threatens veto over budget dispu...

Oregon’s Attorney General Revives Gary Gensler’s Case Against Coinbase: What Next? Steve Muchoki | u...

Spar supermarket pops up on Bitcoin map in Switzerland, becomes mainstream payment option Cryptopoli...

Oregon revives SEC case against Coinbase over securities and staking Jai Hamid | usagoldmines.com

SOL Slips, ADA Flatlines—But This AI-Backed Coin Is Quietly Up 400% and Just Getting Started Cryptop...

Is Pi Network About to Explode Toward $10? Analysts Say Momentum Is Gaining Fast Alejandro Arrieche ...

Dogecoin Charts Flash 2020-Style Bull Signal, Crypto Analyst Says Jake Simmons | usagoldmines.com

Crypto News | Pi Network News Today: April 18th Dimitar Dzhondzhorov | usagoldmines.com

Rugpulls are fewer but more impactful, Mantra Network leads $6B lost funds in 2025 Hannah Collymore ...

White House says Trump is determined to fire Fed’s Powell no matter the cost Jai Hamid | usagoldmine...

Onshore stocks fall in China amid escalating trade tensions with US Enacy Mapakame | usagoldmines.co...

XRP Price Prediction: XRP Bounces From Strong Support.  Next Stop $3 Alongside This Emerging Token? ...

Binance Coin (BNB) Saw 3.28% Surge But Ruvi AI’s (RUVI) $1 Valuation Could Skyrocket Your Portfolio ...

HashKey launches Asia’s first XRP tracker fund with Ripple backing Jai Hamid | usagoldmines.com

Key Indicator Turns Bullish for Ripple’s XRP as the Weekend Kicks Off Olivia Brooke | usagoldmines.c...

Can Quantum Computing Really Kill Bitcoin? $85K Bounty Says It’s Time to Find Out Arslan Butt | usag...

Stablecoin Sinks to $0.68: sUSD Loses Its Peg, Sparks Fears of SNX Death Spiral? Hassan Shittu | usa...

Crypto News | Galaxy Research Proposes Overhaul to Solana’s Inflation Voting System Chayanika Deka ...

Crypto News | Former SEC lawyer warns ending SEC crypto action could trigger bank contagion Liam 'Ak...

Crypto News | BlackRock’s BUIDL drives 92% surge in tokenized US treasury market Oluwapelumi Adejumo...

Crypto News | kiloEx recovers $7.5M after promising attacker 10% bounty Oluwapelumi Adejumo | usagol...

Kyrgyzstan Says Yes to Central Bank Digital Currency — Starts Testing “Digital Som” Mustafa Mulla | ...

Bitwise Brings Bitcoin & Ethereum ETPs on LSE Victor | usagoldmines.com

KiloEX exploiter returned $6.9M after white hat bounty offer Hristina Vasileva | usagoldmines.com

Central Bank of Turkey raises key interest rate to 46%, reversing easing cycle amid tariff worries L...

Houthis used $900 million in crypto to bypass US sanctions, says TRM Labs Cryptopolitan News | usago...

Trump thinks tariffs will revive US manufacturing but economists disagree Randa Moses | usagoldmines...

XRP Coils Below $2.20 Amid ETF Speculation; Meanwhile Investors Accumulate Yeti Ouro Before Price In...

Why Whale Investors Favor Ripple (XRP) and Mutuum Finance (MUTM) Over Solana (SOL) in 2025 Cryptopol...

Binance research: Record US Treasury supply will affect crypto markets in 2025 Hristina Vasileva | u...

Financial Pundit Says India Should Follow US And Hold Bitcoin, SOL, And XRP In Strategic Reserve Bre...

Industry Expert Predicts Bitcoin’s Non-Stop Rocket Surge To $1 Million If the U.S. Purchases One Mil...

Ethereum Price Stalls In Tight Range – Big Price Move Incoming? Sebastian Villafuerte | usagoldmines...

Eliza Labs Reveals a No-Code AI Agent Platform auto.fun Sead Fadilpašić | usagoldmines.com

KiloEx Hacker Returns Entire $7.5M Four Days After Exploit Hassan Shittu | usagoldmines.com

Is XRP About to Break Out? MACD Flip Sparks Fresh Bullish Speculation Arslan Butt | usagoldmines.com

Visa Dethroned: Stablecoins Settle $27.6 Trillion — Ethereum’s Big Win? Hassan Shittu | usagoldmines...

European Blockchain Sandbox Selects Web3 Companies for Third Cohort, Including Privado ID Sead Fadil...

Is Dogecoin About to Explode? Analysts Say a 3-Month Bull Run May Be Starting Alejandro Arrieche | u...

XRP To $50? Technical Analyst Lays Out The Roadmap Christian Encila | usagoldmines.com

Crypto News | Crypto Price Analysis April-18: ETH, XRP, ADA, SOL, and HYPE Duo Nine | usagoldmines....

Crypto News | Hype Over? FARTCOIN Exits Crypto’s Top 100 Club After a 17% Daily Decline Dimitar Dzh...

Crypto News | Moonacy Protocol will sponsor and participate in Blockchain Life 2025 in Dubai Chainw...

Crypto News | BioMatrix Launches iPoY: Pioneering Identity-Driven GameFi in the AI-Powered Web3 Era...

Crypto News | Blocksquare, Vera Capital Partner to Tokenize $1B in US Real Estate Wayne Jones | usa...

Crypto News | Bitcoin holds steady during Good Friday market closure, macro forces shape global risk...

Arbitrum Launches Converge: A New Era for DeFi and RWAs Victor | usagoldmines.com

Bleap and Mastercard Team Up on Stablecoin Payments Tari | usagoldmines.com

XRP Breakout Still Likely This April, Analyst Says $12+ In Play Jake Simmons | usagoldmines.com

ANAP Buys $70 Million in Bitcoin for Treasury Victor | usagoldmines.com

Trump wants a stronger yen in trade negotiations with Japan, and that’s dangerous for both sides Jai...

Galaxy Research unveils proposal to curb Solana inflation through a new voting system Collins J. Oko...

Rugpull Losses Soar 6,500% in 2025 as Crypto Scams Turn Deadlier, Nearly $6B Lost – DappRadar Hassan...

Pump.fun co-founder shuts down token launch expectations in Base content coin response Hannah Collym...

Binance leads CEX market in Q1 with $8.39 trillion in trading volume: report Vignesh Karunanidhi | u...

Ethereum Price Predicted To Rally To $2,600 In Coming Weeks Leading To This ETH Token Skyrocketing C...

Japan’s inflation hits 3.6% YoY in March to exceed the BOJ’s estimates for three straight years Coll...

Elon Musk’s Grok 3 and DeepSeek AI Approve: This Solana (SOL) Competitor Will Skyrocket 12590% Crypt...

Manta founder nearly falls victim to Lazarus led deepfake Zoom scam Ashish Kumar | usagoldmines.com

Bitcoin In Peril? Expert Warns Of China’s Alleged Scheme To Crash BTC To $40,000 Ronaldo Marquez | u...

Crypto News | What Lies Ahead for Pi Network’s Price? Exploring the Bullish and Bearish Cases Dimit...

Crypto News | Asia’s First XRP Tracker Fund Launched by Ripple and HashKey Capital Wayne Jones | us...

Crypto News | BYDFi Officially Launches On-Chain Trading Tool MoonX, Ushering in the Era of CEX + D...

XRP News Today: Ripple Acquires Hidden Road for $1.25B in Major Expansion Move Qadir AK | usagoldmin...

XRP ETF News: HashKey Launches Asia’s First XRP Fund with Ripple’s Backing Mustafa Mulla | usagoldmi...

Pailot Files for Pi Network Mainnet Listing, Eyes Web3 Logistics Breakthrough Vignesh S G | usagoldm...

PiDaoSwap Launch: First DEX on Pi Network’s Mainnet, Here’s What It Offers! Vignesh S G | usagoldmin...

Aave Surpasses $480M on Sonic Labs with 12x Rewards Victor | usagoldmines.com

Leave a Reply