Malicious NPM Package "pdf-to-office" Targets Atomic and Exodus Crypto Wallets
N2K NetworksMay 9, 202518 min149 views
37 connections·40 entities in this video→Malicious NPM Campaign Targeting Crypto Wallets
- 🎯 A malicious npm package named "pdf-to-office" was discovered that targets users of Atomic Wallet and Exodus Wallet.
- 💡 The package's true intent is to trojanize locally installed wallet software, redirecting crypto transfers to attacker-controlled addresses.
Persistence and Payload Delivery
- 🧠 The malicious payload is injected directly into the legitimate wallet software files, meaning it persists even after the npm package is uninstalled.
- ⚠️ This technique bypasses typical defenses that would only look for malicious packages, as the compromise lies within the wallet application itself.
Attack Tactics and Obfuscation
- 🧩 Attackers used a package name that sounds useful ("pdf-to-office") to entice developers to download it.
- 🔍 The package contained obfuscated JavaScript to hide its malicious intent, though the obfuscation was relatively simple to de-obfuscate.
- 📦 The malicious payload within the package was also encoded using Base64.
Scope and Targeting
- 🎯 The campaign specifically targeted the latest two versions of Atomic Wallet and the latest version of Exodus Wallet at the time of discovery.
- 🌍 The attackers did not appear to focus on specific geographic locations, instead checking for the presence of the targeted wallet software on the victim's machine.
Implications for Supply Chain Security
- ⚠️ This incident highlights the growing threat of software supply chain attacks within the cryptocurrency ecosystem, particularly on platforms like npm.
- 💡 It demonstrates a shift from hijacking legitimate packages to a simpler method of injecting payloads into already installed software, making detection and persistence more challenging.
Recommendations for Users and Developers
- 🚨 Users of crypto-related software, including wallets, should be vigilant and aware of ongoing threats.
- 🛠️ If affected, users should remove the malicious npm package and reinstall the targeted versions of their wallet software.
- 🤝 Package managers like npm could improve security by working more closely with threat researchers to identify and remove malicious packages.
Knowledge graph40 entities · 37 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters6 moments
Key Moments
Transcript65 segments
Full Transcript
Topics13 themes
What’s Discussed
NPMMalicious PackagesAtomic WalletExodus WalletCryptocurrencySoftware Supply Chain AttacksTrojanJavaScript ObfuscationPayloadPersistenceReversingLabsCybersecurityMalware
Smart Objects40 · 37 links
Products· 13
Companies· 6
People· 6
Concepts· 13
Media· 1
Event· 1