{"id":4657,"date":"2025-06-14T10:04:47","date_gmt":"2025-06-14T10:04:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/14\/threat-actors-attacking-cryptocurrency-and-blockchain-developers-with-weaponized-npm-and-pypi-packages\/"},"modified":"2025-06-14T10:04:47","modified_gmt":"2025-06-14T10:04:47","slug":"threat-actors-attacking-cryptocurrency-and-blockchain-developers-with-weaponized-npm-and-pypi-packages","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/14\/threat-actors-attacking-cryptocurrency-and-blockchain-developers-with-weaponized-npm-and-pypi-packages\/","title":{"rendered":"Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages"},"content":{"rendered":"<p>    Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cryptocurrency and blockchain development ecosystem is facing an unprecedented surge in sophisticated malware campaigns targeting the open source supply chain.<\/p>\n<p>Over the past year, threat actors have significantly escalated their attacks against Web3 developers by publishing malicious packages to trusted registries including npm and PyPI, exploiting the implicit trust developers place in these repositories.<\/p>\n<p>These campaigns represent a calculated shift toward financially motivated attacks that leverage the unique vulnerabilities present in blockchain development environments.<\/p>\n<p>The attack landscape has become increasingly concentrated, with approximately 75% of malicious blockchain-related packages hosted on npm, 20% on PyPI, and the remainder distributed across registries such as RubyGems and Go Modules.<\/p>\n<p>While Ethereum and Solana continue to be the primary targets, recent campaigns have expanded to include TRON and TON platforms, indicating growing threat actor interest in a wider range of wallet formats and alternative layer-1 blockchain ecosystems.<\/p>\n<p>Socket.dev analysts <a href=\"https:\/\/socket.dev\/blog\/2025-blockchain-and-cryptocurrency-threat-report?utm_medium=feed\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> four recurring threat classes that dominate the current landscape: credential stealers, crypto drainers, cryptojackers, and clipboard hijackers.<\/p>\n<p>These malicious packages exploit the unique attack surface created by blockchain developers\u2019 reliance on open source dependencies, combined with CI\/CD pipelines that often lack strict dependency validation or isolation.<\/p>\n<p>The threat actors leverage package lifecycle hooks such as postinstall in npm and setup.py in PyPI to trigger malicious behavior immediately upon installation, even when packages are never imported or actively used.<\/p>\n<p>The financial impact of these attacks has been severe, with threat actors successfully extracting millions in cryptocurrency from compromised development environments.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> campaigns demonstrate sophisticated understanding of Web3 development workflows, targeting specific wallet paths, browser extensions, and development tools commonly used by blockchain developers.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Credential Theft Mechanisms<\/strong><\/h2>\n<p>The most sophisticated aspect of these supply chain attacks lies in their credential extraction capabilities, which have evolved far beyond simple file system scraping.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgaSnN0oHsyvhcCgOi1gw1RiKGjNeAOmypPOd_DpgH9gdf-m58XPcDU1F0ABQeklodzUX8pJfMafie5LigFw4B8eGGnh9P4NKFj8wN9fpHFyJfSt7T3wZIZeLTXnnT1elqv33BkqRX-91Lh6YxgZri5_CEmuDh3eJ-ag7jj3pqRZzR4IabYICdw6wI2oEU\/s16000\/Contagious%2520Interview%2520attack%2520chain%2520for%2520infiltrating%2520Web3%2520development%2520environments%2520%28Source%2520-%2520Socket.dev%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Contagious Interview attack chain for infiltrating Web3 development environments (Source \u2013 Socket.dev)<\/figcaption><\/figure>\n<\/div>\n<p>Modern credential stealers employ multi-layered approaches that combine direct file system access with runtime manipulation to capture sensitive cryptographic material from developer environments.<\/p>\n<p>Advanced stealers implement monkey-patching techniques that intercept keypair generation at the library level without modifying source files.<\/p>\n<p>In documented PyPI campaigns, malware intercepted Solana keypair creation by modifying library methods at runtime, capturing private keys during generation, encrypting them with hardcoded RSA-2048 public keys, and embedding the encrypted data in <a href=\"https:\/\/cybersecuritynews.com\/blockchain-security-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain<\/a> memo transactions sent to Solana Devnet.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh4_y1kjzrK3cQ_LhXsi4FP3Jej4qFjNqgfmZte387n1H_Nfni_XznA0Djz4RX26t4aEQiaeFVYp1UdmQ5L7cfIjBf5U02cGQnMqI3AEk_yl-rr9Ee3qgTiIW0csPyg09QssmlxXp6n1TP83hTmBqd1iXZfpaZEnRKgJ1kEWsmnmTMR17cfiqSlbBCvMC8\/s16000\/Execution%2520flow%2520of%2520cryptojacking%2520malware%2520%28Source%2520-%2520Socket.dev%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Execution flow of cryptojacking malware (Source \u2013 Socket.dev)<\/figcaption><\/figure>\n<\/div>\n<p>This technique allows threat actors to retrieve and decrypt stolen credentials remotely while maintaining stealth.<\/p>\n<pre class=\"wp-block-code\"><code>\/\/ Example of typical credential stealer targeting common wallet paths\nconst fs = require('fs');\nconst path = require('path');\n\nconst walletPaths = [\n  '~\/.config\/solana\/id.json',\n  '~\/.ledger-live',\n  '~\/Library\/Application Support\/Exodus\/exodus. Wallet'\n];\n\nwalletPaths.forEach(walletPath =&gt; {\n  if (fs.existsSync(path.expanduser(walletPath))) {\n    \/\/ Exfiltrate wallet data via encrypted channels\n  }\n});<\/code><\/pre>\n<p>Nation-state actors, particularly those linked to North Korea\u2019s Contagious Interview <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-campaign-attacking-investors\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a>, have weaponized trusted developer tools including linters, validators, and post-processing libraries to deliver credential stealers and backdoors.<\/p>\n<p>These attacks bypass traditional <a href=\"https:\/\/cybersecuritynews.com\/security-measures-that-help-protect-your-crypto\/\" target=\"_blank\" rel=\"noreferrer noopener\">security measures<\/a> including multi-factor authentication and hardware wallets by compromising the development environment itself, establishing persistence through scheduled tasks and startup entries to ensure recurring access to victim systems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><strong>Automate threat response with ANY.RUN\u2019s TI Feeds\u2014Enrich alerts and block malicious IPs across all endpoints<\/strong>\u00a0-&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=free-vs-paid-ti-feeds&amp;utm_content=plans&amp;utm_term=100625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Request full access<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attacking-cryptocurrency-and-blockchain-developers\/\">Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-attacking-cryptocurrency-and-blockchain-developers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages The cryptocurrency and blockchain development ecosystem is facing an unprecedented surge in sophisticated malware campaigns targeting the open source supply chain. Over the past year, threat actors have significantly escalated their attacks against Web3 developers by publishing malicious packages to trusted registries [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4657","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4657"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4657"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4657\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4657"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4657"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}