30 Jan, 2025

Malicious npm packages target Ethereum developers’ private keys

Twenty malicious packages impersonating the Hardhat development environment used by Ethereum developers are targeting private keys and other sensitive data. Collectively, the malicious packages have recorded more than one thousand downloads, researchers say. Narrow targeting campaign Hardhat is a widely used Ethereum development environment maintained by the Nomic Foundation. It is used for developing, testing, […]

2 mins read

Malicious Microsoft VSCode extensions target devs, crypto community

Malicious Visual Studio Code extensions were discovered on the VSCode marketplace that download heavily obfuscated PowerShell payloads to target developers and cryptocurrency projects in supply chain attacks. In a report by Reversing Labs, researchers say the malicious extensions first appeared in the VSCode marketplace in October. “Throughout October 2024, the RL research team saw a […]

3 mins read