BTC $79,152.25 -0.79%
ETH $2,490.04 -0.09%
BNB $744.74 -0.70%
XRP $1.40 -1.00%
SOL $104.99 -1.76%
TRX $0.3352 +0.07%
DOGE $0.0909 +1.41%
ADA $0.2210 +1.08%
BCH $260.27 +0.68%
LINK $13.15 +6.22%
HYPE $87.54 -2.11%
AAVE $133.33 -1.21%
SUI $0.8273 +3.48%
XLM $0.1926 +3.61%
ZEC $1,178.24 -0.10%
BTC $79,152.25 -0.79%
ETH $2,490.04 -0.09%
BNB $744.74 -0.70%
XRP $1.40 -1.00%
SOL $104.99 -1.76%
TRX $0.3352 +0.07%
DOGE $0.0909 +1.41%
ADA $0.2210 +1.08%
BCH $260.27 +0.68%
LINK $13.15 +6.22%
HYPE $87.54 -2.11%
AAVE $133.33 -1.21%
SUI $0.8273 +3.48%
XLM $0.1926 +3.61%
ZEC $1,178.24 -0.10%

The Socket security team discovered a malicious npm package, and the attacker attempted to steal 85% of the wallet balance assets

2025-06-03 10:18:07

ChainCatcher message, the Socket Security Research Team has discovered four malicious npm packages that target Binance Smart Chain (BSC) and Ethereum users' wallets. These packages are pancakeuniswapvalidatorsutilssnipe (350 downloads), pancakeswap-oracle-prediction (445 downloads), ethereum-smart-contract (305 downloads), and env-process (1,054 downloads), with a total download count exceeding 2,100.

The attackers use obfuscated JavaScript code to calculate the percentage of the target wallet balance and attempt to transfer up to 85% of the assets to a wallet address under their control.

app_icon
ChainCatcher Building the Web3 world with innovations.