logo

Hackers Use Typosquatted npm Packages to Target Web3 Projects and Crypto Wallet Operators

ID: fc0947ec-99ef-5218-98c7-1161224cf918

STIX ID: report--fc0947ec-99ef-5218-98c7-1161224cf918

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Mayura Kathir

...
...

A coordinated typosquatting campaign abused npm packages targeting Web3 developers—using lifecycle hook abuse, obfuscation, remote payload delivery, and on-chain C2—to steal mnemonics, private keys, environment secrets and deliver further malware; the trojanized moralis-sdk (reported with ~2.7M downloads) and multiple impersonating packages are documented along with extensive IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.