Crypto Chaos: 1900+ Duped by Malicious npm Package “Crypto-Encrypt-TS”
Crypto-encrypt-ts, a fake npm package masquerading as CryptoJS, has been discovered stealing crypto and personal data. With over 1900 downloads, it cleverly uses typosquatting to trick users. Sonatype’s research reveals this package accesses wallets and sends sensitive information to attackers, highlighting the need for stronger security measures in software development.

Hot Take:
Looks like someone tried to give CryptoJS a shady makeover. Spoiler alert: it doesn’t just encrypt your data; it also encrypts your trust issues. With nearly 2,000 downloads, this package was stealthily sneaking into systems like it was on a covert mission. Who knew a little typo could lead to such wallet-wrecking drama?
Key Points:
- Sonatype discovered a malicious npm package ‘crypto-encrypt-ts’ impersonating CryptoJS.
- This package aimed to steal cryptocurrency and personal data from unsuspecting users.
- It used the service Better Stack to send stolen data to an attacker-controlled server.
- Code analysis suggested a Turkish origin, with sophisticated methods to steal data.
- Sonatype alerted npm registry, emphasizing the dangers of typosquatting in software.
Already a member? Log in here