Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were discovered on npm and PyPI, distributing stealer malware to developers and end users.
Security researchers identified fraudulent software development kits targeting three major payment platforms on open-source package repositories. The fake packages mimicked legitimate Paysafe, Skrill, and Neteller SDKs, making them difficult to distinguish from authentic versions.
Once installed, the malicious packages deployed stealer malware designed to extract sensitive credentials from compromised systems. The threat affected both developers who integrated the SDKs into applications and end users who may have downloaded them indirectly through compromised dependencies.
The discovery highlights ongoing supply chain vulnerabilities in popular package managers. npm and PyPI, while critical infrastructure for software development, remain targets for attackers distributing malware through typosquatting and package impersonation tactics.
Developers using Paysafe, Skrill, or Neteller payment integrations should audit their dependencies immediately. The repositories have removed the malicious packages, but systems that installed them during the distribution window face potential compromise.
This incident follows a pattern of attacks on package managers. Previous incidents have compromised popular libraries, affecting thousands of downstream projects. Security experts recommend implementing stricter package verification processes, using package signing, and monitoring for suspicious activity in dependency chains.
Organizations handling payment processing should prioritize scanning their codebases for these fake SDKs and rotating any compromised credentials. Both npm and PyPI encourage developers to report suspicious packages immediately and enable two-factor authentication on package accounts.
The incident underscores the need for better vetting mechanisms in open-source repositories and heightened vigilance when installing third-party packages, particularly those related to sensitive operations like payment processing.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.