BTC $65,221.05 +1.19%
ETH $1,963.10 +4.19%
BNB $572.96 +0.43%
XRP $1.11 +0.51%
SOL $76.50 +1.97%
TRX $0.3300 -0.61%
DOGE $0.0727 -0.63%
ADA $0.1651 +0.09%
BCH $218.55 +3.67%
LINK $8.77 +4.25%
HYPE $60.33 +2.74%
AAVE $100.92 +5.17%
SUI $0.7166 -0.16%
XLM $0.1819 +2.19%
ZEC $501.66 +1.92%
BTC $65,221.05 +1.19%
ETH $1,963.10 +4.19%
BNB $572.96 +0.43%
XRP $1.11 +0.51%
SOL $76.50 +1.97%
TRX $0.3300 -0.61%
DOGE $0.0727 -0.63%
ADA $0.1651 +0.09%
BCH $218.55 +3.67%
LINK $8.77 +4.25%
HYPE $60.33 +2.74%
AAVE $100.92 +5.17%
SUI $0.7166 -0.16%
XLM $0.1819 +2.19%
ZEC $501.66 +1.92%

theft

All
Article
Flash

Security Alert: 30 malicious npm packages disguised as trading bot repositories, targeting the theft of developer keys and mnemonic phrases

SlowMist issued a security alert, detecting a coordinated malicious npm supply chain attack. The attackers utilized fake trading bot repositories and DeFi-themed npm packages to deploy JavaScript information stealers, targeting npm users, DeFi developers, and trading bot users.This attack involved 30 malicious npm packages, among which stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository presented approximately 2300 highly homogeneous bulk-generated forks, mostly concentrated under the poly-stocks account, with signals being exceptionally clear. The sensitive data that attackers could steal is extensive, including cryptocurrency wallet libraries, browser cookies and saved passwords, browsing history, developer credentials, shell history, password manager libraries, private keys, mnemonic phrases, and API tokens exposed in source code.SlowMist recommends that developers immediately remove the affected npm packages, audit package.json and package-lock.json, and check CI logs for any of the 30 malicious packages; consider any system that has executed npm install as potentially compromised, rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens, and rebuild the affected environment from a clean image.

The U.S. Congress plans to rebuild the Department of Justice's cybercrime task force to coordinate efforts against related theft and fraud

According to CryptoSlate, the U.S. Congress is pushing to rebuild the Department of Justice's cryptocurrency crime task force. Previously, the Department of Justice disbanded the National Cryptocurrency Enforcement Team in April 2025 and stopped its "law enforcement as regulation" strategy targeting the cryptocurrency industry. The new bill was proposed by Representatives Lance Gooden and Josh Gottheimer, aiming to establish a federal cryptocurrency theft task force within the Department of Justice, responsible for coordinating investigations and prosecutions of cases involving cryptocurrency theft, hacking, fraud, and more.The task force's responsibilities include developing best practices for evidence collection, digital evidence analysis, asset tracking, and victim outreach, providing technical assistance and training to state and local law enforcement agencies, and coordinating international cross-border case cooperation. The bill explicitly excludes the cryptocurrency market, financial institutions, and financial products from the task force's regulatory scope, without changing the existing regulatory framework and criminal law. An FBI report indicates that in 2025, there were 181,565 complaints involving cryptocurrency, with reported losses exceeding $11 billion. The bill has not yet clarified details regarding funding, staffing, and victim response mechanisms.

The second trial of the 660,000 yuan virtual currency theft case in Wuhan, China, has been revised: the main culprit was sentenced to ten years and six months in prison, and the amount stolen was determined based on the actual payment cost incurred by the victim

According to the "Procuratorial Daily," Lin, Zeng, and Dai conspired to use virtual currency trading as a pretext. During the trading process, they secretly filmed the victim's digital wallet private key and, after the virtual currency was credited, secretly logged into the victim's wallet to reverse the transaction, transferring the related virtual currency back to their controlled accounts. The three committed the crime three times, causing the victim a total economic loss of 660,000 yuan.The first-instance court held that in the absence of a clear judicial interpretation regarding the valuation method of virtual currency and sentencing standards, it was inappropriate to directly determine the amount involved as particularly huge based on the victim's purchase amount of 660,000 yuan. Therefore, they sentenced the three based on "other serious circumstances," imposing prison terms ranging from eight years to five years and six months, along with fines. The Hanyang District Procuratorate of Wuhan City in Hubei Province subsequently filed an appeal, which was supported by the Wuhan City Procuratorate.The prosecution argued that the first-instance court applied the law incorrectly and imposed an excessively light sentence. Prosecutor Dai Wentao of the Wuhan City Procuratorate stated that in the case where the victim had a clear loss amount to refer to, it was contradictory and legally erroneous to claim that the value of virtual currency could not be determined. In judicial practice, using the resale price and transaction price as the basis for determining the amount of theft has become mainstream, and determining the value of virtual currency based on the actual cost paid by the victim has factual, legal, and practical basis.The Intermediate Court of Wuhan accepted the prosecution's opinion in the second instance, revoked the corresponding content of the original judgment, and changed the determination of the theft amount to particularly huge. It sentenced the principal offender Lin to ten years and six months in prison for theft, and sentenced the accomplices Zeng and Dai to eight years in prison each, along with fines.
app_icon
ChainCatcher Building the Web3 world with innovations.