Hackers Use Typosquatted npm Packages to Target Web3 Projects and Crypto Wallet Operators
ID: fc0947ec-99ef-5218-98c7-1161224cf918
STIX ID: report--fc0947ec-99ef-5218-98c7-1161224cf918
Feed Name: GBHackers
Threat Score
A coordinated typosquatting campaign abused npm packages targeting Web3 developers—using lifecycle hook abuse, obfuscation, remote payload delivery, and on-chain C2—to steal mnemonics, private keys, environment secrets and deliver further malware; the trojanized moralis-sdk (reported with ~2.7M downloads) and multiple impersonating packages are documented along with extensive IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
