Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Widespread npm Attack Targets Developer Secrets

Widespread npm Attack Targets Developer Secrets

Posted on June 13, 2026 By CWS

The cybersecurity landscape is facing a significant threat with a new wave of supply chain attacks specifically targeting blockchain developers, Web3 teams, and cloud engineers. Researchers have identified a coordinated effort involving multiple malicious npm packages designed to stealthily extract sensitive information from developers as soon as these packages are installed.

Details of the Malicious Campaign

Among the sensitive data at risk are SSH private keys, cloud credentials, wallet phrases, and API tokens. The campaign’s sheer scale is troubling, with one of the implicated packages, moralis-sdk, amassing over 2.7 million downloads before being flagged by researchers.

This widespread reach suggests that numerous developer workstations, CI/CD pipelines, and cloud environments may have been compromised without detection. Analysts from Cyfirma discovered the campaign by identifying suspicious npm packages, ethers-jss and coinbase-wallet-utils, which were crafted to mimic legitimate Ethereum development tools.

Technical Analysis of the Attack

The investigation revealed eleven suspect npm packages connected to the same operation. These packages were grouped into four distinct operational clusters, each using a unique method to target developers. Some exploited npm lifecycle hooks for automatic code execution during installation, while others used obfuscated loaders and Ethereum smart contracts to obscure command-and-control addresses.

Collectively, these packages achieved over 2.72 million downloads, marking this as one of the most impactful npm supply chain attacks in recent times. Despite detection, some packages continued to reach new victims, indicating ongoing active downloads.

Infection Methods and Security Recommendations

The infection strategy was deceptively straightforward. The npm lifecycle scripts, either preinstall or postinstall hooks, triggered malicious code execution the moment a developer initiated an install command, requiring no additional steps from the victim.

The ethers-jss package, for instance, acted as a malicious overlay of the real ethers library. It compromised wallet creation and recovery processes, capturing private keys and mnemonic phrases and transmitting them to an attacker-controlled server via GitHub Codespaces.

Cyfirma advises utilizing the npm install –ignore-scripts flag to thwart automatic script execution during installations. Organizations are also encouraged to implement Software Composition Analysis tools, avoid storing private keys or seed phrases in plaintext, and promptly rotate any exposed credentials.

Furthermore, developers operating in Web3 environments should diligently verify package publisher identities, download histories, and repository ownership before incorporating unfamiliar packages into their projects.

Indicators of compromise, such as SHA1 and SHA256 hashes of the suspect packages, have been identified to aid in detecting potential breaches. These include package archives related to ethers-jss, coinbase-wallet-utils, and others associated with the campaign.

The campaign highlights the necessity for heightened vigilance and robust security measures across software development practices to mitigate such sophisticated threats.

Cyber Security News Tags:API tokens, Blockchain, cloud credentials, cyber threat, Cybersecurity, CYFIRMA, data exfiltration, developer security, Malware, NPM, software development, SSH keys, supply chain attack, typosquatting, Web3

Post navigation

Previous Post: Claude Fable 5 Sparks Industry Debate: Security Concerns Rise
Next Post: Chinese Hackers Exploit Linux Login Systems for Years

Related Posts

Microsoft to Kill Popular Editor Browser Extensions on Edge and Chrome Microsoft to Kill Popular Editor Browser Extensions on Edge and Chrome Cyber Security News
Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users Cyber Security News
New Tool Exploits Windows Service Recovery for Cyber Attacks New Tool Exploits Windows Service Recovery for Cyber Attacks Cyber Security News
Microsoft to End Support for Windows Server 2016 and Windows 10 Microsoft to End Support for Windows Server 2016 and Windows 10 Cyber Security News
Hackers Exploit Google Calendar for AI Security Breach Hackers Exploit Google Calendar for AI Security Breach Cyber Security News
Cybercriminals Exploit Cloud Platforms to Conceal Attacks Cybercriminals Exploit Cloud Platforms to Conceal Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates
  • Tengu Botnet Uses Watchdog to Restart Linux Devices
  • Origin Energy Reports Data Breach Impacting 900,000 Customers
  • Cyera to Acquire Oasis Security in Billion-Dollar Deal

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Aembit Partners with Snowflake for AI Security Enhancement
  • Apple Resolves Numerous Security Flaws in Latest Updates
  • Tengu Botnet Uses Watchdog to Restart Linux Devices
  • Origin Energy Reports Data Breach Impacting 900,000 Customers
  • Cyera to Acquire Oasis Security in Billion-Dollar Deal

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark