According to PANews, cybersecurity experts have identified a new threat targeting users of Atomic and Exodus wallets. Attackers are uploading malicious software packages to online code repositories with the intent to steal cryptocurrency private keys. ReversingLabs security researchers have highlighted that this exploit involves hiding malicious code within seemingly legitimate npm software packages, which are widely used by software developers.
The malicious packages operate by installing patches that lock local installations of Atomic and Exodus wallet files, overwriting original files to manipulate the user interface. This deception aims to trick unsuspecting victims into transferring cryptocurrency to fraudulent addresses. As the cryptocurrency industry continues to grapple with hackers, software supply chain attacks are emerging as a new threat vector against cryptocurrency holders. Attackers are employing increasingly sophisticated methods to evade detection and steal user funds.