Scan to download
BTC $66,797.78 -1.20%
ETH $2,069.69 -0.78%
BNB $597.79 -2.74%
XRP $1.32 -0.95%
SOL $78.65 -4.86%
TRX $0.3151 +0.23%
DOGE $0.0900 -1.86%
ADA $0.2404 -0.73%
BCH $448.13 -2.92%
LINK $8.63 -1.43%
HYPE $35.40 -2.14%
AAVE $94.68 -2.59%
SUI $0.8592 -1.62%
XLM $0.1649 -1.60%
ZEC $243.36 -0.55%
BTC $66,797.78 -1.20%
ETH $2,069.69 -0.78%
BNB $597.79 -2.74%
XRP $1.32 -0.95%
SOL $78.65 -4.86%
TRX $0.3151 +0.23%
DOGE $0.0900 -1.86%
ADA $0.2404 -0.73%
BCH $448.13 -2.92%
LINK $8.63 -1.43%
HYPE $35.40 -2.14%
AAVE $94.68 -2.59%
SUI $0.8592 -1.62%
XLM $0.1649 -1.60%
ZEC $243.36 -0.55%

The Socket security team discovered a malicious npm package, and the attacker attempted to steal 85% of the wallet balance assets

2025-06-03 10:18:07
Collection

ChainCatcher message, the Socket Security Research Team has discovered four malicious npm packages that target Binance Smart Chain (BSC) and Ethereum users' wallets. These packages are pancakeuniswapvalidatorsutilssnipe (350 downloads), pancakeswap-oracle-prediction (445 downloads), ethereum-smart-contract (305 downloads), and env-process (1,054 downloads), with a total download count exceeding 2,100.

The attackers use obfuscated JavaScript code to calculate the percentage of the target wallet balance and attempt to transfer up to 85% of the assets to a wallet address under their control.

app_icon
ChainCatcher Building the Web3 world with innovations.