Malicious Actors are Targeting Atomic and Exodus Wallet Users

Source Beincrypto

Cybercriminals have found a new attack vector, targeting users of Atomic and Exodus wallets through open-source software repositories.

The latest wave of exploits involves distributing malware-laced packages to compromise private keys and drain digital assets.

How Hackers are Targeting Atomic and Exodus Wallets

ReversingLabs, a cybersecurity firm, has uncovered a malicious campaign where attackers compromised Node Package Manager (NPM) libraries.

These libraries, often disguised as legitimate tools like PDF-to-Office converters, carry hidden malware. Once installed, the malicious code executes a multi-phase attack.

First, the software scans the infected device for crypto wallets. Then, it injects harmful code into the system. This includes a clipboard hijacker that silently alters wallet addresses during transactions, rerouting funds to wallets controlled by the attackers.

Malicious Code Targeting Atomic and Exodus Wallets.Malicious Code Targeting Atomic and Exodus Wallets. Source: ReversingLabs

Moreover, the malware also collects system details and monitors how successfully it infiltrated each target. This intelligence allows threat actors to improve their methods and scale future attacks more effectively.

Meanwhile, ReversingLabs also noted that the malware maintains persistence. Even if the deceptive package, such as pdf-to-office, is deleted, remnants of the malicious code remain active.

To fully cleanse a system, users must uninstall affected crypto wallet software and reinstall from verified sources.

Indeed, security experts noted that the scope of the threat highlights the growing software supply chain risks threatening the industry.

“The frequency and sophistication of software supply chain attacks that target the cryptocurrency industry are also a warning sign of what’s to come in other industries. And they’re more evidence of the need for organizations to improve their ability to monitor for software supply chain threats and attacks,” ReversingLabs stated.

This week, Kaspersky researchers reported a parallel campaign using SourceForge, where cybercriminals uploaded fake Microsoft Office installers embedded with malware.

These infected files included clipboard hijackers and crypto miners, posing as legitimate software but operating silently in the background to compromise wallets.

The incidents highlight a surge in open-source abuse and present a disturbing trend of attackers increasingly hiding malware inside software packages developers trust.

Considering the prominence of these attacks, crypto users and developers are urged to remain vigilant, verify software sources, and implement strong security practices to mitigate growing threats.

According to DeFiLlama, over $1.5 billion in crypto assets were lost to exploits in Q1 2025 alone. The largest incident involved a $1.4 billion Bybit breach in February.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Gold Price Forecast: XAU/USD retreats further from all-time highs of $3,245 Gold price is back in the red early Monday, snapping a three-day record rally to lifetime highs of $3,245 set on Friday.    
Author  FXStreet
Yesterday 02: 15
Gold price is back in the red early Monday, snapping a three-day record rally to lifetime highs of $3,245 set on Friday.    
placeholder
TRUMP token leads $906 million in unlocks this week with over $330 million releaseAccording to Tokenomist, 15 altcoins will unlock more than $5 million each in the next 7 days. Wu Blockchain data shows that the total unlocked value exceeds $906 million, of which the TRUMP token will unlock more than $330 million.
Author  FXStreet
Yesterday 05: 59
According to Tokenomist, 15 altcoins will unlock more than $5 million each in the next 7 days. Wu Blockchain data shows that the total unlocked value exceeds $906 million, of which the TRUMP token will unlock more than $330 million.
placeholder
Silver Price Forecast: XAG/USD slides below $32.00; downside potential seems limitedSilver (XAG/USD) attracts some sellers at the start of a new week and slides back below the $32.00 round-figure mark during the Asian session on Monday.
Author  FXStreet
Yesterday 05: 59
Silver (XAG/USD) attracts some sellers at the start of a new week and slides back below the $32.00 round-figure mark during the Asian session on Monday.
placeholder
Why Mantra token’s dramatic 90% crash wiped out $5.2B market shareMantra (OM) price hovered at $0.83 during the Asian session on Monday, following a massive 90% crash from $6.33 on Sunday. The crash wiped out $5.2 billion in the token’s market capitalization, quickly drawing comparisons to the infamous collapse of Terra LUNA and FTX in 2022.
Author  FXStreet
Yesterday 06: 00
Mantra (OM) price hovered at $0.83 during the Asian session on Monday, following a massive 90% crash from $6.33 on Sunday. The crash wiped out $5.2 billion in the token’s market capitalization, quickly drawing comparisons to the infamous collapse of Terra LUNA and FTX in 2022.
placeholder
GBP/USD climbs further beyond 1.3200, highest since October ahead of UK jobs dataThe GBP/USD pair attracts buyers for the sixth straight day and climbs above the 1.3200 mark, hitting a fresh high since October 2024 during the Asian session on Tuesday.
Author  FXStreet
36 mins ago
The GBP/USD pair attracts buyers for the sixth straight day and climbs above the 1.3200 mark, hitting a fresh high since October 2024 during the Asian session on Tuesday.
goTop
quote