Microsoft has issued a warning about attackers hiding crypto-stealing malware in public npm packages, posing a risk to developers, crypto investors, and wallet users. The malware can steal crypto wallet credentials from devices by deploying RAT malware through compromised npm packages. Attackers used Hugging Face repos to move stolen data discreetly. This highlights the ongoing threat of supply chain attacks in the crypto sector.

Leave a Reply