Malicious actors continue to upload malicious packages to the npm registry, with the aim of modifying already installed local versions of legitimate libraries and executing malicious code, in a more underhanded attempt to carry out an attack on the supply chain .
See also: npm packages breached to steal developer data

The newly discovered package, named pdf-to-office, pretends to be a tool for converting PDF files to Microsoft Word documents. However, in reality, it contains capabilities for injecting malicious code into cryptocurrency wallet software related to Atomic Wallet and Exodus.
This particular npm package was first released on March 24, 2025 , and has received three updates since then, but previous versions have likely been removed by the authors themselves. The latest version, 1.1.2 , was uploaded on April 8 and remains available for download. The package has been downloaded 334 times to date .
This revelation comes just a few weeks after the software supply chain security firm discovered two npm packages, named ethers-provider2 and ethers-providerz, which were designed to infect locally installed packages and establish a reverse connection to the threat actor's server via SSH.
See also: Lazarus group infects hundreds via npm packages
What makes this approach attractive to malicious actors is that it allows the malware to remain on developers' systems even after the malicious package is removed

An analysis of pdf-to-office has revealed that the malicious code embedded in the package checks for the existence of the file “ atomic/resources/app.asar ” in the “ AppData/Local/Programs ” folder to confirm that Atomic Wallet is installed on the Windows computer and, if so, to insert the clipper function .
In a similar vein, the payload is also designed to modify the “src/app/ui/index.js” file associated with the Exodus wallet. However, in an interesting twist, the attacks target two specific versions of Atomic Wallet (2.91.5 and 2.90.6) and Exodus (25.13.3 and 25.9.2), in order to ensure that the correct JavaScript files are replaced.
The revelation comes as ExtensionTotal reported 10 malicious Visual Studio Code extensions that secretly download a PowerShell scriptthat disables Windows security, creates persistence via scheduled tasks, and installs an XMRig cryptominer. These extensions had been installed a total of over a million times before they were removed.
See also: Hackers deploy malicious npm packages to steal Solana Wallet Keys
npm malicious packages are packages published to npm (Node Package Manager) with the intent to cause damage, steal data, or gain unauthorized access to systems or applications. They are essentially JavaScript or TypeScript packages that contain malicious code .
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
