216.73.216.36

NuGet malware targets crypto wallets, OAuth tokens

· Published 17/12/2025 21:22 · Modified 21/12/2025 19:35

Export JSON

Essential information

Published
17/12/2025 21:22
Modified
21/12/2025 19:35
Tags
2025-12-17 coinbase.net.api cryptocurrency googleads.api homoglyphs netherеum.all nuget oauth supply chain attack version bumping wallet stealer
Related entities
9 techniques (mitre), 2 others

Description

ReversingLabs discovered malicious packages on targeting the crypto ecosystem. The campaign, starting in July 2025, involved 14 packages impersonating legitimate crypto-related tools. The malware aimed to steal crypto funds by redirecting transactions or exfiltrating secrets for wallet access. Techniques used to appear trustworthy included , , and inflating download counts. The packages were divided into three groups: wallet stealers, crypto-funds stealers, and Google Ads stealers. This campaign highlights the ongoing exploitation of trust in the software supply chain, potentially affecting entire projects and communities relying on compromised dependencies.

External references