logo

Atomic and Exodus crypto wallets targeted in malicious npm campaign

ID: d77bbed9-6837-5a47-a6e4-b0742807b203

STIX ID: report--d77bbed9-6837-5a47-a6e4-b0742807b203

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2025-04-10

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

ReversingLabs discovered an active npm-based supply-chain campaign where a malicious package ('pdf-to-office') patched locally installed crypto wallet software (Atomic Wallet, Exodus) by injecting trojanized files that replace outgoing wallet addresses to divert funds, exhibited persistence after package removal, exfiltrated AnyDesk artifacts, targeted specific wallet versions, and was removed from npm after detection; the report includes IOCs and analysis of the attack techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.