• bitcoinBitcoin (BTC) $ 84,906.00
  • ethereumEthereum (ETH) $ 1,638.56
  • tetherTether (USDT) $ 0.999884
  • xrpXRP (XRP) $ 2.14
  • bnbBNB (BNB) $ 596.17
  • solanaSolana (SOL) $ 130.71
  • usd-coinUSDC (USDC) $ 0.999978
  • dogecoinDogecoin (DOGE) $ 0.166170
  • cardanoCardano (ADA) $ 0.654475
  • tronTRON (TRX) $ 0.246972
  • staked-etherLido Staked Ether (STETH) $ 1,637.52
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 84,942.00
  • leo-tokenLEO Token (LEO) $ 9.33
  • avalanche-2Avalanche (AVAX) $ 20.21
  • chainlinkChainlink (LINK) $ 13.08
  • suiSui (SUI) $ 2.34
  • the-open-networkToncoin (TON) $ 3.03
  • stellarStellar (XLM) $ 0.243179
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • hedera-hashgraphHedera (HBAR) $ 0.171917
  • usdsUSDS (USDS) $ 0.999771
  • wrapped-stethWrapped stETH (WSTETH) $ 1,965.63
  • bitcoin-cashBitcoin Cash (BCH) $ 350.60
  • mantra-daoMANTRA (OM) $ 6.27
  • litecoinLitecoin (LTC) $ 78.57
  • polkadotPolkadot (DOT) $ 3.70
  • hyperliquidHyperliquid (HYPE) $ 16.34
  • bitget-tokenBitget Token (BGB) $ 4.39
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • pi-networkPi Network (PI) $ 0.734473
  • ethena-usdeEthena USDe (USDE) $ 0.999199
  • wethWETH (WETH) $ 1,639.09
  • whitebitWhiteBIT Coin (WBT) $ 27.73
  • moneroMonero (XMR) $ 206.03
  • wrapped-eethWrapped eETH (WEETH) $ 1,744.36
  • uniswapUniswap (UNI) $ 5.50
  • okbOKB (OKB) $ 53.78
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 84,885.00
  • daiDai (DAI) $ 0.999674
  • pepePepe (PEPE) $ 0.000007
  • aptosAptos (APT) $ 4.92
  • ondo-financeOndo (ONDO) $ 0.909304
  • gatechain-tokenGate (GT) $ 22.69
  • nearNEAR Protocol (NEAR) $ 2.20
  • tokenize-xchangeTokenize Xchange (TKX) $ 32.92
  • internet-computerInternet Computer (ICP) $ 5.20
  • susdssUSDS (SUSDS) $ 1.05
  • crypto-com-chainCronos (CRO) $ 0.089507
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • mantleMantle (MNT) $ 0.714947
  • ethereum-classicEthereum Classic (ETC) $ 15.53
  • aaveAave (AAVE) $ 147.90
  • bittensorBittensor (TAO) $ 255.69
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.16
  • render-tokenRender (RENDER) $ 3.90
  • vechainVeChain (VET) $ 0.023014
  • kaspaKaspa (KAS) $ 0.075099
  • cosmosCosmos Hub (ATOM) $ 4.28
  • ethenaEthena (ENA) $ 0.335383
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 84,881.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998038
  • fasttokenFasttoken (FTN) $ 4.05
  • official-trumpOfficial Trump (TRUMP) $ 8.45
  • filecoinFilecoin (FIL) $ 2.55
  • sonic-3Sonic (prev. FTM) (S) $ 0.517097
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.188529
  • algorandAlgorand (ALGO) $ 0.188447
  • celestiaCelestia (TIA) $ 2.62
  • arbitrumArbitrum (ARB) $ 0.307201
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 3.79
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 84,672.00
  • kucoin-sharesKuCoin (KCS) $ 10.51
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.482459
  • makerMaker (MKR) $ 1,396.77
  • xdce-crowd-saleXDC Network (XDC) $ 0.074734
  • jupiter-exchange-solanaJupiter (JUP) $ 0.405001
  • optimismOptimism (OP) $ 0.686005
  • story-2Story (IP) $ 4.23
  • binance-staked-solBinance Staked SOL (BNSOL) $ 136.24
  • nexoNEXO (NEXO) $ 1.05
  • eosEOS (EOS) $ 0.688281
  • bonkBonk (BONK) $ 0.000013
  • usdt0USDT0 (USDT0) $ 0.999738
  • binance-peg-wethBinance-Peg WETH (WETH) $ 1,639.20
  • blockstackStacks (STX) $ 0.646466
  • worldcoin-wldWorldcoin (WLD) $ 0.776701
  • flare-networksFlare (FLR) $ 0.015233
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 1,705.16
  • fartcoinFartcoin (FARTCOIN) $ 0.911107
  • sei-networkSei (SEI) $ 0.176848
  • dexeDeXe (DEXE) $ 14.89
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999425
  • movementMovement (MOVE) $ 0.337215
  • curve-dao-tokenCurve DAO (CRV) $ 0.622809
  • injective-protocolInjective (INJ) $ 8.37
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.999710
  • tether-goldTether Gold (XAUT) $ 3,237.95
  • rocket-pool-ethRocket Pool ETH (RETH) $ 1,847.85
  • jasmycoinJasmyCoin (JASMY) $ 0.016359

New Trojan Alert Affecting Cryptocurrency Users – Don’t Download the File With This Name!

0 0

New Trojan Alert Affecting Cryptocurrency Users – Don’t Download the File With This Name!

In response to a growing wave of cyberattacks targeting the cryptocurrency community, threat actors have launched a sophisticated software supply chain aimed at compromising widely used Web3 wallets, including Atomic Wallet and Exodus.

According to researchers at ReversingLabs (RL), the malicious campaign centers on the npm package manager, a popular platform for JavaScript and Node.js developers. Attackers are installing a deceptive package called pdf-to-office, which is falsely promoted as a utility for converting PDF files to Microsoft Office formats. Instead, the package carries malicious code designed to hijack local installations of legitimate crypto wallet software.

Once executed, the pdf-to-office suite silently injects malicious patches into locally installed versions of Atomic Wallet and Exodus. These patches replace the legitimate code with a modified version that allows attackers to intercept and redirect cryptocurrency transactions. In practice, users attempting to send funds would find that their transactions were being redirected to a wallet controlled by the attackers, with no visible signs of tampering.

The attack exploited a subtle and increasingly popular technique: Instead of directly hijacking upstream open-source packages, malicious actors now inject malicious code into local environments by patching legitimate software already installed on the victim’s system.

The pdf-to-office package first appeared on npm in March 2025 and has had multiple versions released in succession. The latest version, 1.1.2, was released on April 1. RL researchers detected the package using machine learning-driven behavioral analysis on the Spectra Assure platform. The code was found to contain obfuscated JavaScript, a common red flag in recent npm malware campaigns.

Notably, the effects persisted even after the malicious package was deleted. Once the Web3 wallets were patched, simply removing the fake npm package did not eliminate the threat. Victims had to completely uninstall and reinstall their wallet application to remove the trojan components and restore wallet integrity.

*This is not investment advice.

Source

Leave A Reply

Your email address will not be published.