Cryptocurrency
Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster
Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.
ViteVenom: Scoped npm Packages Impersonate @vitejs to Deliver a Blockchain-C2 RAT
Checkmarx tracks ViteVenom, a sequel to the ChainVeil campaign, in which seven scoped npm packages impersonating the @vitejs namespace deploy a RAT that fetches its C2 address from Tron and Aptos blockchain transactions.
Injective Labs' @injectivelabs/sdk-ts npm Package Backdoored to Steal Wallet Private Keys
A compromised release of Injective Labs' TypeScript SDK, @injectivelabs/sdk-ts, and 17 dependent packages hooked wallet key-derivation functions to exfiltrate mnemonic seed phrases and private keys to an endpoint disguised as legitimate Injective infrastructure.