< Back to all clusters
[TECHNOLOGY] · 2 sources

Microsoft warns of crypto‑stealing malware hidden in npm packages

Microsoft Threat Intelligence identified two compromised npm packages, utils‑terminal @ 3.2.1 and logger‑active @ 3.2.1 (also referenced as [email protected] and [email protected]), that deliver a remote‑access trojan (RAT). The malware captures keystrokes, screenshots and cryptocurrency wallet credentials, and exfiltrates the data through legitimate Hugging Face API endpoints, making the traffic appear benign.

The campaign targets developers and organizations that install these public dependencies, exposing browser‑based wallets, private keys, seed phrases, exchange API tokens and cloud service credentials. Microsoft warned that the threat adds to ongoing software‑supply‑chain risks for JavaScript developers and crypto users worldwide. It recommends reviewing newly added packages, rotating potentially exposed credentials and monitoring wallet activity for unauthorized transactions.