SlowMist: Detected malicious supply chain attacks targeting npm users and DeFi developers
Foresight News reported that according to monitoring by SlowMist, MistEye detected a coordinated malicious npm supply chain activity. The activity uses fake trading bot code repositories and DeFi-themed npm packages to deliver JavaScript information-stealing tools to npm users, DeFi developers, and trading bot users.
This activity involves 30 malicious npm packages, including stake-math@3.5.4, which appears as a locked dependency in donoaccestag/forex-mt5-trading-bot. The code repository exhibits clear abnormal signals: it depends on npm packages that have been reported as malicious, and there are about 2,300 highly homogeneous forks—likely mass generated—mainly concentrated under the poly-stocks account.
Potential attacker actions include stealing local sensitive data such as crypto wallets, browser cookies, saved passwords, browsing history, developer credentials, shell history, password manager vaults, private keys, mnemonic phrases, and API tokens found in source code. Developers should immediately remove affected npm packages, audit package.json / package-lock.json and CI logs for these 30 malicious packages, treat any system on which npm install was run as a potential victim, promptly replace exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Market Chatter: Exxon Mobil Anticipates Higher LNG Sales Despite Middle East War
Market Chatter: Anthropic Signs $13.7 Billion Computing Deal With Trump-Linked Rum Group
Deutsche Bank survey shows rising confidence in London capital markets, UK IPO outlook improves
Tellusgruppen agrees to buy Sandvikens Friskola for up to SEK 34.7 million
