As cited
Copy frozen at (site build).
threat intel
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Attackers uploaded malicious packages impersonating Paysafe, Skrill, and Neteller payment SDKs to npm and PyPI repositories. The fake packages contained stealer malware designed to capture credentials from developers and end users of these financial services.
Why it matters: Developers who installed these packages exposed their applications and customers' payment credentials to theft. Organizations using these payment integrations should audit their supply chain dependencies and revoke any potentially compromised tokens or API keys.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages impersonating software development kits (SDKs) for Paysafe, Skrill, and Neteller payment services were distributed via npm and PyPI. The packages contained stealer malware designed to exfiltrate credentials from developers and application users.
Why it matters: Developers who installed these fake SDKs face credential compromise and potential account takeover; practitioners should audit npm and PyPI dependencies for these impostor packages and revoke any exposed credentials immediately.
- Source published
- First seen by Cybersecurity Tracker