• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

More than 200 cryptomining packages flood npm and PyPI registry

19 August 2022
in Mining
Reading Time: 3 mins read
A A
0
More than 200 cryptomining packages flood npm and PyPI registry
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Sonatype has spotted 186 malicious packages flooding the npm registry today. These packages infect Linux hosts with cryptominers by downloading a malicious Bash script from the threat actor’s server via the Bitly URL shortener service. Our discovery follows another researcher’s discovery of 55 PyPI packages from this week, that also pull crypto miners in an identical fashion from the same offending URL.

186 counterfeit npm packages drop cryptominers

Today, Sonatype’s automated malware detection systems flagged 186 npm packages that all impersonate the heavily used http-errors JavaScript library that gets downloaded over 50 million times on a weekly basis.

The complete list of 186 packages we identified is present in this PDF.

All of these packages were published from a pseudonymous npm account called “17b4a931.”

Many of these packages are typosquats and target users of known libraries like React (typosquat being ‘r2act’) and QT (via ‘qtt’ typosquat).

More than 200 cryptomining packages flood npm and PyPI registry

The index.js file contained within these packages shows they are in fact pulling the legitimate ‘http-errors’ library from npm, so as to not raise eyebrows. But, let’s admit, the names of these packages are drastically different from ‘http-errors’ no matter how impressive a job they may do in impersonating the project’s README verbatim.

Scrolling down past a few lines of code reveals some sinister activity:

On Line 115, we see the packages are pulling content from a Bit.ly URL and silently executing this script while muting its output (via >/dev/null).

The developer behind these malicious packages has even left a snarky comment in the code, acknowledging the malware, being a Bash script, would run on Unix-based systems only:

“if ur using windows for installing this package ur 1 lucky son of a *****”

And the Bit.ly URL redirects to the address shown below:

https://bit[.]ly/3c2tMTT => http://80.78.25[. (Read more…)

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: CryptoMiningfloodnpmPackagesPyPIRegistry
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

XRP Loses 10%, Drops Below Binance’s Stablecoin by Market Cap

Next Post

Russian Hospital Employee ‘Mined Crypto in a COVID-19 Ward’; SBI Crypto to Halt Mining in Russia

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Russian Hospital Employee ‘Mined Crypto in a COVID-19 Ward’; SBI Crypto to Halt Mining in Russia

Russian Hospital Employee ‘Mined Crypto in a COVID-19 Ward’; SBI Crypto to Halt Mining in Russia

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Streamer Gets Slapped by Gym Influencer Bradley Martyn, Pumping Solana Token – Yahoo Finance

Streamer Gets Slapped by Gym Influencer Bradley Martyn, Pumping Solana Token – Yahoo Finance

12 September 2025
Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

12 September 2025
Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to ,000?

Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to $1,000?

12 September 2025
Solana Surges as TVL Hits B and Market Cap Overtakes BNB – CoinCentral

Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Streamer Gets Slapped by Gym Influencer Bradley Martyn, Pumping Solana Token – Yahoo Finance
  • Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk
  • Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to $1,000?
  • Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral
  • Most big cryptocurrencies rise as Solana rallies – MarketWatch

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 116,075.00
  • ethereumEthereum (ETH) $ 4,642.25
  • xrpXRP (XRP) $ 3.10
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 239.64
  • bnbBNB (BNB) $ 923.71
  • usd-coinUSDC (USDC) $ 0.999716
  • dogecoinDogecoin (DOGE) $ 0.271424
  • staked-etherLido Staked Ether (STETH) $ 4,635.26
  • tronTRON (TRX) $ 0.350465
  • cardanoCardano (ADA) $ 0.902924
  • wrapped-stethWrapped stETH (WSTETH) $ 5,624.80
  • chainlinkChainlink (LINK) $ 24.95
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 5,007.87
  • hyperliquidHyperliquid (HYPE) $ 55.82
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 116,200.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.68
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.01
  • stellarStellar (XLM) $ 0.398513
  • wrapped-eethWrapped eETH (WEETH) $ 4,989.23
  • avalanche-2Avalanche (AVAX) $ 28.57
  • bitcoin-cashBitcoin Cash (BCH) $ 596.84
  • wethWETH (WETH) $ 4,643.39
  • hedera-hashgraphHedera (HBAR) $ 0.243099
  • litecoinLitecoin (LTC) $ 117.09
  • leo-tokenLEO Token (LEO) $ 9.59
  • crypto-com-chainCronos (CRO) $ 0.254683
  • the-open-networkToncoin (TON) $ 3.21
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • usdsUSDS (USDS) $ 0.999452
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 116,151.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.26
  • whitebitWhiteBIT Coin (WBT) $ 44.25
  • uniswapUniswap (UNI) $ 10.07
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.205540
  • ethenaEthena (ENA) $ 0.773003
  • mantleMantle (MNT) $ 1.65
  • moneroMonero (XMR) $ 278.73
  • aaveAave (AAVE) $ 317.86
  • pepePepe (PEPE) $ 0.000011
  • bitget-tokenBitget Token (BGB) $ 4.92
  • daiDai (DAI) $ 1.00
  • okbOKB (OKB) $ 198.69
  • memecoreMemeCore (M) $ 2.23
  • jito-staked-solJito Staked SOL (JITOSOL) $ 295.26
  • nearNEAR Protocol (NEAR) $ 2.78
  • ondo-financeOndo (ONDO) $ 1.10