Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Widespread npm Attack Targets Developer Secrets

Widespread npm Attack Targets Developer Secrets

Posted on June 13, 2026 By CWS

The cybersecurity landscape is facing a significant threat with a new wave of supply chain attacks specifically targeting blockchain developers, Web3 teams, and cloud engineers. Researchers have identified a coordinated effort involving multiple malicious npm packages designed to stealthily extract sensitive information from developers as soon as these packages are installed.

Details of the Malicious Campaign

Among the sensitive data at risk are SSH private keys, cloud credentials, wallet phrases, and API tokens. The campaign’s sheer scale is troubling, with one of the implicated packages, moralis-sdk, amassing over 2.7 million downloads before being flagged by researchers.

This widespread reach suggests that numerous developer workstations, CI/CD pipelines, and cloud environments may have been compromised without detection. Analysts from Cyfirma discovered the campaign by identifying suspicious npm packages, ethers-jss and coinbase-wallet-utils, which were crafted to mimic legitimate Ethereum development tools.

Technical Analysis of the Attack

The investigation revealed eleven suspect npm packages connected to the same operation. These packages were grouped into four distinct operational clusters, each using a unique method to target developers. Some exploited npm lifecycle hooks for automatic code execution during installation, while others used obfuscated loaders and Ethereum smart contracts to obscure command-and-control addresses.

Collectively, these packages achieved over 2.72 million downloads, marking this as one of the most impactful npm supply chain attacks in recent times. Despite detection, some packages continued to reach new victims, indicating ongoing active downloads.

Infection Methods and Security Recommendations

The infection strategy was deceptively straightforward. The npm lifecycle scripts, either preinstall or postinstall hooks, triggered malicious code execution the moment a developer initiated an install command, requiring no additional steps from the victim.

The ethers-jss package, for instance, acted as a malicious overlay of the real ethers library. It compromised wallet creation and recovery processes, capturing private keys and mnemonic phrases and transmitting them to an attacker-controlled server via GitHub Codespaces.

Cyfirma advises utilizing the npm install –ignore-scripts flag to thwart automatic script execution during installations. Organizations are also encouraged to implement Software Composition Analysis tools, avoid storing private keys or seed phrases in plaintext, and promptly rotate any exposed credentials.

Furthermore, developers operating in Web3 environments should diligently verify package publisher identities, download histories, and repository ownership before incorporating unfamiliar packages into their projects.

Indicators of compromise, such as SHA1 and SHA256 hashes of the suspect packages, have been identified to aid in detecting potential breaches. These include package archives related to ethers-jss, coinbase-wallet-utils, and others associated with the campaign.

The campaign highlights the necessity for heightened vigilance and robust security measures across software development practices to mitigate such sophisticated threats.

Cyber Security News Tags:API tokens, Blockchain, cloud credentials, cyber threat, Cybersecurity, CYFIRMA, data exfiltration, developer security, Malware, NPM, software development, SSH keys, supply chain attack, typosquatting, Web3

Post navigation

Previous Post: Claude Fable 5 Sparks Industry Debate: Security Concerns Rise
Next Post: Chinese Hackers Exploit Linux Login Systems for Years

Related Posts

Top Spam Filter Tools for 2026: A Comprehensive Guide Top Spam Filter Tools for 2026: A Comprehensive Guide Cyber Security News
10 Best API Monitoring Tools in 2025 10 Best API Monitoring Tools in 2025 Cyber Security News
13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System 13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System Cyber Security News
Critical Gogs Vulnerability Allows Remote Code Execution Critical Gogs Vulnerability Allows Remote Code Execution Cyber Security News
ClickFix Uses Legacy Python Tool for Resilient Cyber Attacks ClickFix Uses Legacy Python Tool for Resilient Cyber Attacks Cyber Security News
Lazarus Group’s IT Workers Scheme Hacker Group Caught Live On Camera Lazarus Group’s IT Workers Scheme Hacker Group Caught Live On Camera Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark