Hijacking wallets with malicious patches. [Research Saturday] episode artwork

EPISODE · May 10, 2025 · 17 MIN

Hijacking wallets with malicious patches. [Research Saturday]

from CyberWire Daily · host N2K Networks

This week, we are joined by Lucija Valentić, Software Threat Researcher from ReversingLabs, who is discussing "Atomic and Exodus crypto wallets targeted in malicious npm campaign." Threat actors have launched a malicious npm campaign targeting Atomic and Exodus crypto wallets by distributing a fake package called "pdf-to-office," which secretly patches locally installed wallet software to redirect crypto transfers to attacker-controlled addresses. ReversingLabs researchers discovered that this package used obfuscated JavaScript to trojanize specific files in targeted wallet versions, enabling persistence even after the malicious package was removed. This incident highlights the growing threat of software supply chain attacks in the cryptocurrency space and underscores the need for vigilant monitoring of both open-source repositories and local applications. The research can be found here: ⁠⁠Atomic and Exodus crypto wallets targeted in malicious npm campaign

Episode metadata supplied by the publisher feed · Published May 10, 2025

Embed this episode

NOW PLAYING

Hijacking wallets with malicious patches. [Research Saturday]

0:00 17:09

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CyberWire Daily?

This episode is 17 minutes long.

When was this CyberWire Daily episode published?

This episode was published on May 10, 2025.

Can I download this CyberWire Daily episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!