HomeSecurityMalicious npm package mimics popular Nodemailer

Malicious npm package mimics popular Nodemailer

Security researchers at Socket.dev have uncovered a sophisticated supply chain attackthat uses a malicious npm package called nodejs-smtp and mimics the widely used Nodemailer (with approximately 3.9 million weekly downloads).

Nodemailer Malicious npm package

nodejs-smtp works exactly like the legitimate library, providing a familiar API and successfully sending emails. This seemingly legitimate functionality acts as a Trojan Horse , with the malicious package engaging in covert actions targeting crypto wallets on Windows desktops .

As organizations continue to integrate open-source dependencies into their development pipelines, attackers are exploiting import-time tampering. Socket.dev analysts observed that upon import, nodejs-smtp immediately triggers an Electron-based payloaddesigned to infiltrate wallets such as Atomic Wallet and Exodus. By decompressing the app.asar archive, replacing a critical vendor bundle with malicious code, and repackaging the file, the attacker ensures persistence and secrecy.

See also: PyPI: Malicious packages exploit dependency for supply chain attacks

After this manipulation, any transaction originating from the compromised wallet is redirected, replacing the intended recipient address with one controlled by the attacker. Socket.dev analysts further discovered that the attacker, operating under the alias npm nikotimon, embeds hardcoded wallet addresses directly into the incoming payload. These addresses include Bitcoin, Ethereum, Tether (both ERC-20 and TRC-20), XRP, and Solana, facilitating multichain theft.

Malicious npm package mimics popular Nodemailer

Although initial downloads for the malicious npm package (nodejs-smtp) were relatively low — around 342 at the time of discovery — the potential for widespread compromise remains high given the frequent presence of Nodemailer in production environments.

Deeper analysis of the nodejs-smtp infection strategy reveals a two-step process that exploits Electron's packaging format:

  • In the first stage, the package's lib/engine/index.js script is executed immediately upon import. This routine decompresses the wallet archive, replaces the vendor bundle with the malicious a.js , and repackages the integrity-checked archive to cover its tracks.
  • On the next wallet launch, a.js intercepts the transaction construction and replaces the recipient address, ensuring that any outgoing payments are diverted. Because execution occurs on import, nodejs-smtp avoids detection by static scanners that only inspect function calls at runtime. This persistent, import-time hook highlights the evolving threat landscape within open source ecosystems, underscoring the need for security measures with a focus on the supply chain.

See also: Toptal GitHub account hacked – Publishing malicious npm packages (+Update)

Nodemailer at risk: Protection measures

In light of these findings, developers and security teams are urged to adopt robust supply chain defenses. Recommended measures include real-time analysis of side-effect imports, strict enforcement of code review policies for new dependencies, and the development of automated tools to spot file manipulation patterns during package installation.

Malicious npm package mimics popular Nodemailer

The risk is compounded by the fact that build pipelines and continuous integration systems are unlikely to detect the threat when dependencies appear to be functionally correct.

See also: North Korean hackers distribute 67 malicious npm packages

The case of the malicious nodejs-smtp package dramatically highlights how vulnerable the software supply chain can become when it relies on open-source dependencies without strict controls. Its similarity to the popular Nodemailer is no coincidence; attackers know well that a library with millions of weekly downloads is an ideal vehicle for mass dissemination.

In a world where even an “innocent” npm install can pave the way for crypto theft, the concept of trust in open source needs to be redefined. Cybercriminals are constantly finding new ways to trick users and infiltrate systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS