Skip to content

Three Malicious NPM Packages Attacking Developers to Steal Login Credentials

Cybersecuritynews Tushar Subhra Dutta January 8, 2026

Three malicious npm packages are targeting JavaScript developers to steal browser logins, API keys, and cryptocurrency wallet data. The packages, named bitcoin-main-lib, bitcoin-lib-js, and bip40, were uploaded to the public npm registry and posed as tools linked to the popular bitcoinjs project. Any developer who added them as dependencies could silently install a new remote […]

Extracted Entities