Typosquatted npm and PyPI Packages Steal Secrets from Payment-App Developers

· Original article ↗

Summary

Socket detected 17 malicious npm and PyPI packages targeting developers of PaySafe, Skrill and Neteller apps. The packages steal credentials and environment secrets, using sandbox evasion and Ngrok infrastructure for exfiltration.

Key points

  • The 17 malicious packages were published nearly simultaneously on July 7, 2026, targeting SDK users of PaySafe, Skrill and Neteller.
  • The packages mimic payment SDKs but return fabricated success responses rather than making real payment API calls.
  • They collect environment variables containing terms such as KEY, SECRET, TOKEN, PASS, AUTH or API, along with host and user details; npm exfiltration requires a Paysafe API key, while PyPI packages activate without one.
  • The malware avoids execution in some sandboxes and obfuscates its C2 address, which uses an Ngrok free-domain hostname.
  • Socket reports that all listed npm package versions were detected as malware within six minutes of publication.
  • Recommended actions include searching dependency trees for the packages, rotating secrets on machines that imported or executed them, and investigating outbound HTTPS connections to the listed Ngrok domain.

Article Details

Attack Vectors
  • Seventeen malicious packages were published nearly simultaneously across two public package ecosystems, using payment SDK branding to attract developers and users.
  • The fake SDK facade returned successful-looking payment and customer responses without contacting real payment endpoints.
  • The JavaScript payload executed credential exfiltration after an SDK request when an API key was configured. The article reports that the Python packages activated through their initialization files without requiring an API key.
  • The payloads harvested environment variables whose names contained KEY, SECRET, TOKEN, PASS, AUTH, or API, truncating each captured value to 100 characters.
  • The payloads sent stolen secrets and host fingerprints as JSON over outbound HTTPS to a C2 endpoint.
Defensive Notes
  • Rotate all secrets on machines that imported or executed the malicious packages, especially environment variables matching the payload's harvesting filters.
  • Search dependency trees for the listed malicious packages and block them at the registry proxy level.
  • Hunt for unusual outbound HTTPS connections from build and CI hosts to the tunnel-hosting infrastructure identified in the indicators.
  • Audit CI logs for payment API key usage alongside the listed malicious packages.
  • The JavaScript payload skipped exfiltration on systems with fewer than two CPU cores or sandbox-related hostname or username strings; the Python example checked hostname strings.
  • The article reports that obfuscation keys differed across package versions, limiting detection based on a reused key.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEcaliber-spinner-finishing[.]ngrok-free[.]devC2 hostname explicitly listed under network indicators.
SHA2561314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23Malicious index.js artifact listed in the file indicators.
SHA2561bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bcMalicious index.js artifact listed in the file indicators.
SHA2561bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410Malicious index.js artifact listed in the file indicators.
SHA2561d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89Malicious index.js artifact listed in the file indicators.
SHA2561df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501bMalicious index.js artifact listed in the file indicators.
SHA2562303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7Malicious index.js artifact listed in the file indicators.
SHA2562b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982Malicious index.js artifact listed in the file indicators.
SHA2562bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bdMalicious index.js artifact listed in the file indicators.
SHA2562cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0edMalicious index.js artifact listed in the file indicators.
SHA2562edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213dMalicious index.js artifact listed in the file indicators.
SHA256313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14Malicious index.js artifact listed in the file indicators.
SHA256390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3Malicious index.js artifact listed in the file indicators.
SHA25639371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1Malicious index.js artifact listed in the file indicators.
SHA2563a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0Malicious index.js artifact listed in the file indicators.
SHA256447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5Malicious index.js artifact listed in the file indicators.
SHA2564a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0Malicious index.js artifact listed in the file indicators.
SHA25650cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048Malicious index.js artifact listed in the file indicators.
SHA2565242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23Malicious index.js artifact listed in the file indicators.
SHA25652a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405Malicious index.js artifact listed in the file indicators.
SHA2565c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85Malicious index.js artifact listed in the file indicators.
SHA2565cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9Malicious index.js artifact listed in the file indicators.
SHA256615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369Malicious index.js artifact listed in the file indicators.
SHA256616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528eMalicious index.js artifact listed in the file indicators.
SHA25661b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63Malicious index.js artifact listed in the file indicators.
SHA25667e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4Malicious index.js artifact listed in the file indicators.
SHA25667eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5Malicious index.js artifact listed in the file indicators.
SHA2566dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5Malicious index.js artifact listed in the file indicators.
SHA2566e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1Malicious index.js artifact listed in the file indicators.
SHA256727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697Malicious index.js artifact listed in the file indicators.
SHA2568a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188bMalicious index.js artifact listed in the file indicators.
SHA2568a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43Malicious index.js artifact listed in the file indicators.
SHA2569727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94Malicious index.js artifact listed in the file indicators.
SHA2569e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9Malicious index.js artifact listed in the file indicators.
SHA2569fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cfMalicious index.js artifact listed in the file indicators.
SHA256a0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120cMalicious index.js artifact listed in the file indicators.
SHA256a677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8Malicious index.js artifact listed in the file indicators.
SHA256af66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304Malicious index.js artifact listed in the file indicators.
SHA256b04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785Malicious __init__.py artifact listed in the file indicators.
SHA256b157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0Malicious index.js artifact listed in the file indicators.
SHA256b29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aadMalicious index.js artifact listed in the file indicators.
SHA256b2ea8d69f6792a87327ffde2ee4551bb6b99617f53e1ba71bf9a70f45dbc57eaMalicious index.js artifact listed in the file indicators.
SHA256c2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1Malicious __init__.py artifact listed in the file indicators.
SHA256c2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023deMalicious index.js artifact listed in the file indicators.
SHA256c2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151Malicious index.js artifact listed in the file indicators.
SHA256c51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987Malicious index.js artifact listed in the file indicators.
SHA256c6af37a6739f0d919ab7049caf3a85831cab44bdbea27e0d9de7adec80334e2bMalicious __init__.py artifact listed in the file indicators.
SHA256c8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83Malicious index.js artifact listed in the file indicators.
SHA256cd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723adMalicious index.js artifact listed in the file indicators.
SHA256ce09810adca70ebec87bc455380ef629ceaa2a0d926149d9115604060167682cMalicious index.js artifact listed in the file indicators.
SHA256d1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2Malicious index.js artifact listed in the file indicators.
SHA256d4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25Malicious index.js artifact listed in the file indicators.
SHA256dabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5Malicious __init__.py artifact listed in the file indicators.
SHA256e076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9Malicious index.js artifact listed in the file indicators.
SHA256eae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bccMalicious index.js artifact listed in the file indicators.
SHA256f43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418Malicious index.js artifact listed in the file indicators.
SHA256f7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35caMalicious index.js artifact listed in the file indicators.
URLhxxps[:]//caliber-spinner-finishing[.]ngrok-free[.]dev/Credential-exfiltration endpoint explicitly listed under network indicators.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe C2 hostname was concealed with Base64, XOR, character shifting, and reversal; obfuscation keys varied across versions and packages.T1033 · System Owner/User DiscoveryThe payload obtained the current username for sandbox checks and included it in the exfiltrated victim fingerprint.T1036 · MasqueradingThe packages impersonated payment SDKs, exposing fake client methods and legitimate-looking endpoint strings while returning fabricated success responses.T1041 · Exfiltration Over C2 ChannelThe payload uploaded harvested environment secrets, API key fragments, and host fingerprints to its C2 endpoint.T1071.001 · Web ProtocolsThe malicious packages communicated with their C2 endpoint using HTTPS requests on port 443 with JSON bodies.T1082 · System Information DiscoveryThe payload inspected CPU count and collected the victim hostname for sandbox checks and exfiltrated host fingerprints.T1140 · Deobfuscate/Decode Files or InformationThe payload decoded and transformed embedded strings at runtime to reconstruct its C2 hostname.T1195.001 · Compromise Software Dependencies and Development ToolsThe attacker published malicious payment SDK packages on npm and PyPI to reach developers through software dependencies.T1497.001 · System ChecksThe JavaScript payload checked CPU count and sandbox-related hostname or username strings before exfiltration; the Python example checked hostname strings.T1552 · Unsecured CredentialsThe payload harvested API keys, passwords, secrets, and tokens directly from matching environment variables on developer machines and CI runners.

Malware

Vendors

Products

Related Articles