Skip to main content

Malicious NPM Package "pdf-to-office" Targets Atomic and Exodus Crypto Wallets

N2K NetworksMay 9, 202518 min149 views
37 connections·40 entities in this video

Malicious NPM Campaign Targeting Crypto Wallets

  • 🎯 A malicious npm package named "pdf-to-office" was discovered that targets users of Atomic Wallet and Exodus Wallet.
  • 💡 The package's true intent is to trojanize locally installed wallet software, redirecting crypto transfers to attacker-controlled addresses.

Persistence and Payload Delivery

  • 🧠 The malicious payload is injected directly into the legitimate wallet software files, meaning it persists even after the npm package is uninstalled.
  • ⚠️ This technique bypasses typical defenses that would only look for malicious packages, as the compromise lies within the wallet application itself.

Attack Tactics and Obfuscation

  • 🧩 Attackers used a package name that sounds useful ("pdf-to-office") to entice developers to download it.
  • 🔍 The package contained obfuscated JavaScript to hide its malicious intent, though the obfuscation was relatively simple to de-obfuscate.
  • 📦 The malicious payload within the package was also encoded using Base64.

Scope and Targeting

  • 🎯 The campaign specifically targeted the latest two versions of Atomic Wallet and the latest version of Exodus Wallet at the time of discovery.
  • 🌍 The attackers did not appear to focus on specific geographic locations, instead checking for the presence of the targeted wallet software on the victim's machine.

Implications for Supply Chain Security

  • ⚠️ This incident highlights the growing threat of software supply chain attacks within the cryptocurrency ecosystem, particularly on platforms like npm.
  • 💡 It demonstrates a shift from hijacking legitimate packages to a simpler method of injecting payloads into already installed software, making detection and persistence more challenging.

Recommendations for Users and Developers

  • 🚨 Users of crypto-related software, including wallets, should be vigilant and aware of ongoing threats.
  • 🛠️ If affected, users should remove the malicious npm package and reinstall the targeted versions of their wallet software.
  • 🤝 Package managers like npm could improve security by working more closely with threat researchers to identify and remove malicious packages.
Knowledge graph40 entities · 37 connections

How they connect

An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.

Hover · drag to explore
40 entities
Chapters6 moments

Key Moments

Transcript65 segments

Full Transcript

Topics13 themes

What’s Discussed

NPMMalicious PackagesAtomic WalletExodus WalletCryptocurrencySoftware Supply Chain AttacksTrojanJavaScript ObfuscationPayloadPersistenceReversingLabsCybersecurityMalware
Smart Objects40 · 37 links
Products· 13
Companies· 6
People· 6
Concepts· 13
Media· 1
Event· 1