ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

Fake Paysafe/Skrill SDK packages on npm and PyPI steal credentials

Source headline: Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 month ago

Intelligence Summary

Threat actors published fraudulent Paysafe and Skrill SDK packages on npm and PyPI. The malicious packages were designed to capture credentials from developers and users of related payment applications. Victims may unknowingly expose login data and session details when installing and using these dependencies. The campaign targets payment workflows for Paysafe, Skrill, and Neteller ecosystems. Users should avoid untrusted packages, verify package provenance, and rotate any potentially exposed credentials.

Recommended Action

Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#credential-theft #supply-chain #npm #malicious-packages #payment-applications #pypi
Original reporting BleepingComputer Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Open original source