Bogus Google Play pages tapped for SpyNote malware distribution https://t.co/wsbjZNxeY8
COMMENT: Researchers discovered a malicious npm package called pdf-to-office, posing as a PDF tool but designed to inject malware into local crypto wallets and steal funds. https://t.co/ITUq7LHwMV
EXODUS AND ATOMIC USERS AT RISK DUE TO NEW SUPPLY CHAIN ATTACK - A new software supply chain attack is targeting Exodus and Atomic Wallet users, per ReversingLabs. - The threat? Malicious npm packages designed to steal your private keys by tampering with your local wallet https://t.co/9JtBwySVjm
A series of recent cyberattacks have targeted cryptocurrency users, with a focus on malware distribution through fake software and malicious packages. Europol's Operation Endgame has resulted in the arrest of over five clients linked to the SmokeLoader malware, which has been associated with ransomware, spyware, and cryptocurrency theft. This operation follows a broader trend of increasing threats, including the emergence of new malware loaders such as ModiLoader, GootLoader, and FakeUpdates, which are being used for phishing and drive-by attacks. Additionally, users of Exodus and Atomic Wallets are at risk due to a new supply chain attack involving malicious npm packages. These packages are designed to compromise local wallets and steal private keys, posing a significant threat to users' funds. The malicious npm package known as pdf-to-office, masquerading as a PDF tool, has been identified as a key vector in this attack.