Microsoft Alerts on npm Malware Targeting Cryptocurrency Wallets
ID: a34eaa98-20f7-533e-a39b-7d94ebf9f99f
STIX ID: report--a34eaa98-20f7-533e-a39b-7d94ebf9f99f
Feed Name: ThreatCluster
Threat Score
Microsoft warns of a high-severity npm supply-chain campaign delivering a remote access Trojan through two compromised packages; the malware captures keystrokes, screenshots, and wallet credentials, exfiltrating data via the Hugging Face platform. Developers are urged to audit and remove suspicious dependencies, rotate credentials, and monitor wallet activity to mitigate theft and broader account compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
