• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Cybersecurity Researchers Uncover Malicious npm Package Targeting Cryptocurrency Wallets
Share
  • bitcoinBitcoin(BTC)$114,974.00
  • ethereumEthereum(ETH)$4,518.11
  • rippleXRP(XRP)$3.05
  • tetherTether(USDT)$1.00
  • solanaSolana(SOL)$238.13
  • binancecoinBNB(BNB)$907.82
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.260393
  • staked-etherLido Staked Ether(STETH)$4,510.41
  • tronTRON(TRX)$0.348500
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

Cybersecurity Researchers Uncover Malicious npm Package Targeting Cryptocurrency Wallets

News Desk
Last updated: September 3, 2025 11:30 am
News Desk
Published: September 3, 2025
Share
crypto wallter

Cybersecurity researchers have recently uncovered a malicious npm package that poses significant risks to cryptocurrency wallet applications on Windows systems. This nefarious package, named nodejs-smtp, is designed to inject harmful code into popular wallets like Atomic and Exodus, raising alarms across the tech community.

The malicious package was cunningly crafted to imitate the legitimate email library nodemailer, featuring identical taglines, page styling, and README descriptions. Despite being uploaded to the npm registry in April 2025 by a user identified as “nikotimon,” the package has since been taken down. During its short lifespan, it garnered a total of 347 downloads, suggesting a wider threat to developers who may have unknowingly utilized it.

When imported, the package employs Electron tooling to manipulate the Atomic Wallet’s app.asar file. It replaces a legitimate vendor bundle with a malicious payload, subsequently repackaging the application and erasing any evidence of tampering by deleting its working directory. According to Kirill Boychenko, a researcher at Socket, this intricate process serves a nefarious purpose: to redirect transactions from unsuspecting users to hard-coded wallet addresses controlled by the threat actors.

The threat remains particularly pernicious as it enables the redirection of various cryptocurrency transactions, including Bitcoin (BTC), Ethereum (ETH), Tether (USDT and TRX USDT), XRP, and Solana (SOL). This makes the package functionally act as a cryptocurrency clipper, siphoning funds from vulnerable users.

Despite its malicious intent, nodejs-smtp fulfills its advertised function of acting as an SMTP-based mailer. This functional facade reduces developer suspicion, allowing application tests to pass without red flags. The package provides a drop-in interface that aligns with the nodemailer API, hence offering little reason for developers to question its legitimacy.

This discovery follows a previous alarming incident where another npm package, named “pdf-to-office,” was identified with similar capabilities. It demonstrated the potential for malware to infiltrate developer workstations and targeted the same cryptocurrency wallets by modifying JavaScript files within app.asar archives.

Boychenko warns that the current campaign showcases the vulnerability developers face while managing dependencies in their projects. “A routine import on a developer workstation can quietly modify a separate desktop application and persist across reboots,” he noted. By taking advantage of the import time execution and Electron packaging, an ostensibly harmless mailer can transform into a wallet drainer, severely impacting users who rely on trusted cryptocurrency wallets for their digital assets.

Dogecoin Eyes $1 as New Altcoin Remittix Gains Traction
Robin Energy Allocates $5 Million to Bitcoin, Stock Surges Nearly 100%
Crypto Market Recovers as Memecoins Rally Amid Mixed Economic Signals
Bitget COO Vugar Usi Zade Talks Blockchain Education at TEDx Manila
Klarna Shares Surge 30% in Successful New York IPO Debut, Valued at $19.65 Billion
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article HM3V2FOVJJGB3PPK5BESPFS2TY SEC Reviews XRP ETF Applications as Analyst Predicts $5 Billion in Inflows
Next Article WVGYAKGTUBCN5DL3LA4TDUQUWA Ethereum’s Volatility Poised for Turbulence Amid Price Rally
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
market bear bull 01 Large
Euro Struggles Amid US Dollar Bounce as Jobless Claims Rise
e54b9966cbd3cc065a7852ad647d7adb44ca589f 2360x1640
US Posts $345 Billion Deficit as Debt Servicing Costs Rise Amid Fed Rate Cut Speculation
3e0c35e1f92d50c768933a106d222c56
Ray Dalio Advocates for Gold as a Hedge Against Debt and Market Instability
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Blockchain
  • DeFi
  • Stocks
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?