BTC $79,389.39 -0.66%
ETH $2,488.30 -0.52%
BNB $744.36 -1.82%
XRP $1.40 -1.55%
SOL $104.93 -1.45%
TRX $0.3363 +0.42%
DOGE $0.0897 -0.30%
ADA $0.2192 -0.68%
BCH $256.12 -1.73%
LINK $13.18 +7.38%
HYPE $87.81 -0.94%
AAVE $133.78 -1.29%
SUI $0.8085 +0.66%
XLM $0.1908 +2.05%
ZEC $1,193.20 +0.69%
BTC $79,389.39 -0.66%
ETH $2,488.30 -0.52%
BNB $744.36 -1.82%
XRP $1.40 -1.55%
SOL $104.93 -1.45%
TRX $0.3363 +0.42%
DOGE $0.0897 -0.30%
ADA $0.2192 -0.68%
BCH $256.12 -1.73%
LINK $13.18 +7.38%
HYPE $87.81 -0.94%
AAVE $133.78 -1.29%
SUI $0.8085 +0.66%
XLM $0.1908 +2.05%
ZEC $1,193.20 +0.69%

The Socket security team discovered a malicious npm package, and the attacker attempted to steal 85% of the wallet balance assets

2025-06-03 10:18:07

ChainCatcher message, the Socket Security Research Team has discovered four malicious npm packages that target Binance Smart Chain (BSC) and Ethereum users' wallets. These packages are pancakeuniswapvalidatorsutilssnipe (350 downloads), pancakeswap-oracle-prediction (445 downloads), ethereum-smart-contract (305 downloads), and env-process (1,054 downloads), with a total download count exceeding 2,100.

The attackers use obfuscated JavaScript code to calculate the percentage of the target wallet balance and attempt to transfer up to 85% of the assets to a wallet address under their control.

app_icon
ChainCatcher Building the Web3 world with innovations.