Skip to content

Malicious NPM Packages Target Crypto Developers

Posted on:January 21, 2026 at 04:00 PM

TLDR: Security researchers have identified a cluster of malicious NPM packages mimicking popular crypto libraries. The packages contain obfuscated code that exfiltrates environment variables and wallet seed phrases.

Malicious Packages Identified:

Over 15,000 downloads recorded before removal. Developers should audit their dependencies immediately.