logo

Open Source Poisoned Patches Infect Local Software

ID: ded04d29-e548-5994-a400-3d2c2a57cf26

STIX ID: report--ded04d29-e548-5994-a400-3d2c2a57cf26

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-04-10

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers observed malicious npm packages that stealthily patch locally installed software: pdf-to-office searches for Atomic and Exodus wallets and replaces a wallet component to redirect outgoing transactions to attacker-controlled addresses, while ethers-providerz and ethers-provider2 inject code into the ethers library to provide a reverse shell. This poisoned-patching technique is persistent (the wallet remains compromised after removal of the malicious package) and is a stealthy supply-chain style tactic that can enable theft and remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.