At least 17 malicious packages impersonating Paysafe, Skrill, and Neteller payment SDKs were published across npm and PyPI. The packages appeared functional by exposing expected APIs and returning fake success responses, while secretly exfiltrating credentials including Paysafe API keys, AWS keys, GitHub tokens, npm tokens, and system metadata to an AWS-hosted C2 server. The npm packages activate only when a Paysafe API key is detected, while PyPI packages run the theft routine immediately on initialization. Basic anti-analysis checks (CPU core count, hostname/username patterns) are included. Developers who installed any of the 17 listed packages are advised to immediately rotate all secrets, audit dependency trees, and check CI logs for signs of compromise.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
256 Impressions