Crypto Catastrophe: Malicious npm Package Drains Wallets with a Stealthy Purr
Beware of fake npm packages! The sneaky nodejs-smtp mimics nodemailer while secretly draining cryptocurrency wallets like Atomic and Exodus. It acts as a mailer but packs a malicious punch, rerouting Bitcoin, Ethereum, and more to hackers. Developers, double-check your imports before your crypto takes an unexpected trip!

Hot Take:
It’s like a plot twist in a bad techno-thriller: npm packages moonlighting as cryptocurrency thieves. Who knew your friendly neighborhood mailer was actually a secret agent for wallet-draining mischief? Looks like developers need to start treating npm packages like a box of chocolates—you never know what you’re gonna get!
Key Points:
- A malicious npm package, named
nodejs-smtp
, was discovered impersonating the legitimatenodemailer
library. - It targeted cryptocurrency wallets, like Atomic and Exodus, on Windows systems.
- The stealthy package downloads reached 347 before it was removed from the npm registry.
- It cleverly functioned as an SMTP-based mailer while secretly redirecting cryptocurrency transactions.
- This isn’t the first time—similar attacks were noted with a package named “pdf-to-office.”
Already a member? Log in here