BTC $62,775.10 -1.23%
ETH $1,874.15 -0.34%
BNB $604.11 -0.96%
XRP $1.00 -0.41%
SOL $75.45 -0.26%
TRX $0.3331 -0.13%
DOGE $0.0693 -1.08%
ADA $0.1795 -2.69%
BCH $205.25 -3.69%
LINK $8.80 +0.61%
HYPE $56.59 -1.35%
AAVE $86.52 -2.56%
SUI $0.6760 -1.66%
XLM $0.1587 -1.24%
ZEC $486.75 -1.41%
BTC $62,775.10 -1.23%
ETH $1,874.15 -0.34%
BNB $604.11 -0.96%
XRP $1.00 -0.41%
SOL $75.45 -0.26%
TRX $0.3331 -0.13%
DOGE $0.0693 -1.08%
ADA $0.1795 -2.69%
BCH $205.25 -3.69%
LINK $8.80 +0.61%
HYPE $56.59 -1.35%
AAVE $86.52 -2.56%
SUI $0.6760 -1.66%
XLM $0.1587 -1.24%
ZEC $486.75 -1.41%

The Socket security team discovered a malicious npm package, and the attacker attempted to steal 85% of the wallet balance assets

2025-06-03 10:18:07

ChainCatcher message, the Socket Security Research Team has discovered four malicious npm packages that target Binance Smart Chain (BSC) and Ethereum users' wallets. These packages are pancakeuniswapvalidatorsutilssnipe (350 downloads), pancakeswap-oracle-prediction (445 downloads), ethereum-smart-contract (305 downloads), and env-process (1,054 downloads), with a total download count exceeding 2,100.

The attackers use obfuscated JavaScript code to calculate the percentage of the target wallet balance and attempt to transfer up to 85% of the assets to a wallet address under their control.

app_icon
ChainCatcher Building the Web3 world with innovations.