đ¨ Over 2,100 downloads! Malicious npm packages draining crypto wallets
Socket Threat Research reports 4 malicious npm packages targeting Ethereum and BSC devs:
pancake_uniswap_validators_utils_snipe (350 DLs)
pancakeswap-oracle-prediction (445 DLs)
ethereum-smart-contract (305 DLs)
env-process (1054 DLs)
đ¸ Attackers use obfuscated JS to drain 80-85% of wallet balances, redirecting funds to attacker-controlled addresses.
â ď¸ Same actor, active for 3â4 years.
đ Devs: use automated dependency scanning + credential management to stay safe!