Microsoft Warns of Crypto-Stealing Malware Hidden in npm Packages
Microsoft Threat Intelligence has warned of a new malware campaign that uses two compromised npm packages ([email protected] and [email protected]) to deploy a remote access trojan (RAT) capable of stealing keystrokes, screenshots and cryptocurrency wallet credentials. Attackers reportedly route stolen data through Hugging Face repositories, making exfiltration harder to detect. The exploit targets developer workstations (browser wallets, private keys, API keys, cloud/GitHub tokens), heightening software supply-chain risk for crypto projects and retail/institutional holders. Market impact: elevated security concerns could increase demand for custody solutions and hardware wallets, prompt credential rotations and heightened due diligence by funds and exchanges, and create short-term bearish pressure on confidence in self-custody and developer-run services. Broader implications include renewed focus on dependency auditing and tighter operational security across the crypto ecosystem.