By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts
Tech News

Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts

By Viral Trending Content 3 Min Read
Share
SHARE

Mar 28, 2025Ravie LakshmananCryptocurrency / Developer Security

npm Packages Hijacked

Cybersecurity researchers have discovered several cryptocurrency packages on the npm registry that have been hijacked to siphon sensitive information such as environment variables from compromised systems.

“Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers,” Sonatype researcher Ax Sharma said. “However, […] the latest versions of each of these packages were laden with obfuscated scripts.”

Cybersecurity

The affected packages and their hijacked versions are listed below –

  • country-currency-map (2.1.8)
  • bnb-javascript-sdk-nobroadcast (2.16.16)
  • @bithighlander/bitcoin-cash-js-lib (5.2.2)
  • eslint-config-travix (6.3.1)
  • @crosswise-finance1/sdk-v2 (0.1.21)
  • @keepkey/device-protocol (7.13.3)
  • @veniceswap/uikit (0.65.34)
  • @veniceswap/eslint-config-pancake (1.6.2)
  • babel-preset-travix (1.2.1)
  • @travix/ui-themes (1.1.5)
  • @coinmasters/types (4.8.16)

Analysis of these packages by the software supply chain security firm has revealed that they have been poisoned with heavily obfuscated code in two different scripts: “package/scripts/launch.js” and “package/scripts/diagnostic-report.js.”

npm Packages Hijacked

The JavaScript code, which run immediately after the packages are installed, are designed to harvest sensitive data such as API keys, access tokens, SSH keys, and exfiltrate them to a remote server (“eoi2ectd5a5tn1h.m.pipedream[.]net”).

Interestingly, none of the GitHub repositories associated with the libraries have been modified to include the same changes, raising questions as to how the threat actors behind the campaign managed to push malicious code. It’s currently not known what the end goal of the campaign is.

“We hypothesize the cause of the hijack to be old npm maintainer accounts getting compromised either via credential stuffing (which is where threat actors retry usernames and passwords leaked in previous breaches to compromise accounts on other websites), or an expired domain takeover,” Sharma said.

Cybersecurity

“Given the concurrent timing of the attacks on multiple projects from distinct maintainers, the first scenario (maintainer accounts takeover) appears to be more likely as opposed to well-orchestrated phishing attacks.”

The findings underscore the need for securing accounts with two-factor authentication (2FA) to prevent takeover attacks. They also highlight the challenges associated with enforcing such security safeguards when open-source projects reach end-of-life or are no longer actively maintained.

“The case highlights a pressing need for improved supply chain security measures and greater vigilance in monitoring third-party software registries developers,” Sharma said. “Organizations must prioritize security at every stage of the development process to mitigate risks associated with third-party dependencies.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Google Just Launched its MacBook Neo Trump Card

Why Apple’s Next Smart Glasses Won’t Have a Display

Hackers exploit file upload bug in Breeze Cache WordPress plugin

Europe’s public sector deploying AI faster than it can manage – report

The Best Outdoor Deals From the REI Anniversary Sale 2026

TAGGED: Credential stuffing, cryptocurrency, Cyber Security, Cybersecurity, Data Exfiltration, Developer Security, Internet, JavaScript, npm Registry, Open Source, Software Supply Chain
Share This Article
Facebook Twitter Copy Link
Previous Article “Very Angry, Pissed Off” With Putin Over Ukraine War, Says Trump
Next Article Trump’s promised “Liberation Day” of tariffs is coming. Here’s what it could mean for you.
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Bitcoin slips towards $79K as higher Treasury yields and oil prices pressure trigger risk-off sentiment
Business
Andalusia campaign ends after final stretch marked by messages and controversy
World News
Sharplink CEO points out 3 catalysts for Ethereum's price to surge higher
Crypto
Bitcoin Exchange Supply Remains At 8-Year Lows: Bullish Sign?
Crypto
EA Sports UFC 6 Deep Dive Trailer Details Signature Movements, Combat Styles, and More
Gaming News
Who Controls Cuba’s Economy? What to Know About GAESA.
World News
‘Perverted’ Forced Organ Harvesting Gets Spotlight in Congress
Politics

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Bitcoin slips towards $79K as higher Treasury yields and oil prices pressure trigger risk-off sentiment

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Bitcoin slips towards $79K as higher Treasury yields and oil prices pressure trigger risk-off sentiment
May 16, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?