Bleepingcomputer Malicious SDK Packages Target Paysafe, Skrill, and Neteller Users
Article Content
- •17 malicious packages were identified on npm and PyPI, impersonating payment SDKs.
- •The malware targets developers by stealing API keys and tokens from their environments.
- •Immediate action is recommended for affected developers to rotate secrets and check dependencies.
A coordinated malware campaign has been identified, involving 17 malicious packages on npm and PyPI masquerading as legitimate SDKs for Paysafe, Skrill, and Neteller. These packages were designed to exfiltrate sensitive credentials, including API keys and tokens, from developers' environments. The npm packages included four versions, while the PyPI packages contained a single version. The malicious code activates upon initialization, with npm packages triggering only if a Paysafe API key is present. The stolen data is sent to a command-and-control server hosted on AWS. Security researchers from Socket have issued warnings about the potential for further attacks due to the technical capabilities of the threat actor. Developers are advised to rotate all secrets and search dependency trees for the malicious packages. The attack highlights vulnerabilities in the software supply chain, particularly in popular development ecosystems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…