Today's Core Dump is brought to you by ThreatPerspective

The Hacker News

Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys

A new set of four malicious packages have been discovered in the npm package registry with capabilities to steal cryptocurrency wallet credentials from Ethereum developers. "The packages masquerade as legitimate cryptographic utilities and Flashbots MEV infrastructure while secretly exfiltrating private keys and mnemonic seeds to a Telegram bot controlled by the threat actor," Socket researcher

Published: 2025-09-06T12:12:00











© Segmentation Fault . All rights reserved.

Privacy | Terms of Use | Contact Us