Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
ID: dbea70c3-237c-55c9-9c7e-6968fc0d5b53
STIX ID: report--dbea70c3-237c-55c9-9c7e-6968fc0d5b53
Feed Name: Bleeping Computer
Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published to npm and PyPI (17 packages total) and contained stealer malware that returns fake success responses while searching for and exfiltrating secrets — including Paysafe API keys, AWS keys, GitHub and npm tokens — to an AWS-hosted C2. The npm variants activate when a Paysafe API key is present and include basic anti-analysis checks; the PyPI variants run on import. Researchers advise immediate secret rotation for any systems that installed or executed these packages, searching dependency trees and CI logs for the package names and PAYSAFE_API_KEY, and blocking the malicious package names at registry proxies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
