• Bitcoin eyes $100K as Trump teases major trade…
  • SEC’s Crenshaw slams Ripple settlement, warns of ‘regulatory…
  • Ethereum (ETH) Soars Above $2000; What’s Next?
  • MicroStrategy is Up 75% in a Month As…
  • Bitcoin eyes $100K as Trump teases major trade…
  • SEC’s Crenshaw slams Ripple settlement, warns of ‘regulatory…
  • Ethereum (ETH) Soars Above $2000; What’s Next?
  • MicroStrategy is Up 75% in a Month As…
  • Bitcoin eyes $100K as Trump teases major trade…
  • SEC’s Crenshaw slams Ripple settlement, warns of ‘regulatory…
  • Ethereum (ETH) Soars Above $2000; What’s Next?
  • MicroStrategy is Up 75% in a Month As…
Lets Talk Web3 Your trusted source for all things Web3
  • Latest Post
    • Bitcoin News
    • Ethereum News
    • Altcoin News
    • Blockchain News
  • About Us
  • AI News
  • Press Release
  • NFT News
  • Market Analysis
☰
Lets Talk Web3

We also offer the following services:

👉Global Media Coverage: We secure top-tier media placements worldwide. Need specific media houses? Let’s discuss your targets.
👉Content Strategies & Management: From crafting compelling narratives to managing your content, we ensure your message resonates.
👉Shilling Services: Drive constant visibility with strategic Twitter and Binance Square posts.
👉Organic Engagement Boosters: Amplify your presence on Twitter and Telegram with authentic, organic engagement.
👉Exchange Listings: We facilitate smooth and strategic exchange listings to help you reach the right markets.
👉Performance Marketing: Target Web3-focused websites with precision marketing that delivers results.
👉KOL (Key Opinion Leader) Partnerships: With connections to over 5,000 KOLs across various platforms, we can craft a strategy that suits your audience and goals.

Block a time here- https://lnkd.in/g7iCgq_b or email at Contact@letstalkweb3.com

New Malicious Campaign Targets Atomic and Exodus Wallets

Nitin Gupta - Blockchain - April 11, 2025
⚠
Nitin Gupta Founder of LetsTalkWeb3.com, a full fledged media house for everything Web3.…
13 views 5 mins 0 Comments


The security firm ReversingLabs’ research team has discovered yet another campaign targeting specific versions of the popular crypto wallets Exodus and Atomic.

According to the report, threat actors “have been targeting the cryptocurrency community hard lately.” They’re using various methods to hijack popular and legitimate crypto packages to loot people’s wallets.

However, the researchers highlight that hijacking open-source packages is difficult due to the size of the open-source software (OSS) developer community. The tampered-with OSS packages will be detected.

🧵 RL researchers have identified yet another #npm package that uses malicious patching of local software to hijack #cryptocurrency transfers. Get the full story.👇 https://t.co/lbyNR5cp8Z

— ReversingLabs (@ReversingLabs) April 10, 2025

Therefore, threat actors are working hard to make their methods more obscure. A new technique that ReversingLabs discovered is uploading packages to OSS repositories and having them apply malicious ‘patches’ to local versions of legitimate libraries.

The goal is the same: install an unnoticeable malicious code in a popular, trusted local library.

The researchers found “a number of campaigns” in recent weeks attempting this strategy. Notably, on 1 April, a malicious entity published a package, pdf-to-office, to the npm package manager. This package posed as a library for converting PDF to Microsoft Office documents.

Once executed, it would inject malicious code into locally installed Atomic Wallet and Exodus. It would overwrite existing files. “Effectively, a victim who tried to send crypto funds to another wallet would have the intended destination address swapped out for one belonging to the malicious actor,” the report states.

List of TH policies in package pdf-to-office@1.0.2. Source: ReversingLabs

Additionally, this campaign is quite similar to the one the researchers discussed in a research post in March.

In both of these cases, the malicious campaign had no effect on the official Atomic Wallet and Exodus Wallet installers available on the websites.

You might also like
N.Korean Hackers Boost Crypto-Looting Methods: Hiding Malware in GitHub, NPM Packages

Aiming for Specific Wallet Versions

ReversingLabs first detected the pdf-to-office package after its update to npm on 1 April. It was removed soon after detection. But a couple of days later, the threat actor published a new version that looked like the first one. They released three versions of the package over a few weeks in March and April with the same functionality.

The malicious payload worked to detect the presence of the atomic/resources/app.asar archive inside AppData/Local/Programs directory. Finding it would mean that the unsuspecting user installed Atomic Wallet on their now-infected computer.

Then, the malicious code searched for the archive to overwrite one of its files with a trojanized version that changes the outgoing crypto address. Now, the funds would go straight to the threat actor’s wallet.

“That was the only difference between the legitimate and trojanized file, except that the malicious version of the file was not minified,” the report notes.

The difference between a legitimate and trojanized file. Source: ReversingLabs

Additionally, the threat actors focused on specific versions of Atomic. The attack code would adjust which files were overwritten based on the wallet version it found.

Moreover, there was a malicious payload that attempted to inject a trojanized file inside a legitimate, locally-installed Exodus wallet. It targeted the two latest versions of Exodus.

Also, if the victim removed the package pdf-to-office from the computer, the Web3 wallets’ software would still remain compromised. This means it would continue directing crypto to the attackers’ wallet.

“The only way to completely remove the malicious trojanized files from the Web3 wallets’ software would be to remove them completely from the computer and re-install them,” ReversingLabs concludes.

Meanwhile, North Korea’s Lazarus group has been targeting crypto developers via npm supply chain attacks for months in a highly sophisticated global campaign to steal funds and data.

You might also like
Crypto Mining Malware and Open Source Malware Packages Doubled in Q1 2025

The post New Malicious Campaign Targets Atomic and Exodus Wallets appeared first on Cryptonews.



Source link

TAGS:
PREVIOUS
Bitcoin price could underperform stocks as ETF outflows continue
NEXT
Vitalik Buterin unveils roadmap for Ethereum privacy
Related Post
Hedera-Linked Crypto Foundation, OnlyFans Founder Enter Late Bidding War for TikTok: Report
April 3, 2025
Hedera-Linked Crypto Foundation, OnlyFans Founder Enter Late Bidding War for TikTok: Report
Circle Introduces NFT Support on Solana and New Sample App for Programmable Wallets
September 5, 2024
Circle Introduces NFT Support on Solana and New Sample App for Programmable Wallets
Trump Hikes China Tariffs to 125%, Grants 90-Day Delay for Other Nations
April 10, 2025
Trump Hikes China Tariffs to 125%, Grants 90-Day Delay for Other Nations
White House Crypto & AI Czar Meets UAE Officials to Discuss Tech, Investment Plans
March 21, 2025
White House Crypto & AI Czar Meets UAE Officials to Discuss Tech, Investment Plans
Comments are closed.

With a global network of contributors, LetsTalkWeb3 is committed to providing high-quality content that serves both newcomers and seasoned professionals. Whether you’re an investor, developer, or simply curious about the future of the internet, LetsTalkWeb3 is your trusted source for all things Web3

Scroll To Top
  • Home
  • About Us
  • AI News
  • Press Release
  • NFT News
  • Market Analysis
© Copyright 2025 - Lets Talk Web3 . All Rights Reserved
bitcoin
Bitcoin (BTC) $ 102,878.56
ethereum
Ethereum (ETH) $ 2,216.24
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.32
bnb
BNB (BNB) $ 627.63
solana
Solana (SOL) $ 163.09
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.196095
cardano
Cardano (ADA) $ 0.766531
tron
TRON (TRX) $ 0.256932
bitcoin
Bitcoin (BTC) $ 102,878.56
ethereum
Ethereum (ETH) $ 2,216.24
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.32
bnb
BNB (BNB) $ 627.63
solana
Solana (SOL) $ 163.09
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.196095
cardano
Cardano (ADA) $ 0.766531
tron
TRON (TRX) $ 0.256932