Typosquatted npm and PyPI Packages Steal Secrets from Payment-App Developers

Summary
Socket detected 17 malicious npm and PyPI packages targeting developers of PaySafe, Skrill and Neteller apps. The packages steal credentials and environment secrets, using sandbox evasion and Ngrok infrastructure for exfiltration.
Key points
- The 17 malicious packages were published nearly simultaneously on July 7, 2026, targeting SDK users of PaySafe, Skrill and Neteller.
- The packages mimic payment SDKs but return fabricated success responses rather than making real payment API calls.
- They collect environment variables containing terms such as KEY, SECRET, TOKEN, PASS, AUTH or API, along with host and user details; npm exfiltration requires a Paysafe API key, while PyPI packages activate without one.
- The malware avoids execution in some sandboxes and obfuscates its C2 address, which uses an Ngrok free-domain hostname.
- Socket reports that all listed npm package versions were detected as malware within six minutes of publication.
- Recommended actions include searching dependency trees for the packages, rotating secrets on machines that imported or executed them, and investigating outbound HTTPS connections to the listed Ngrok domain.
Article Details
- Attack Vectors
- Seventeen malicious packages were published nearly simultaneously across two public package ecosystems, using payment SDK branding to attract developers and users.
- The fake SDK facade returned successful-looking payment and customer responses without contacting real payment endpoints.
- The JavaScript payload executed credential exfiltration after an SDK request when an API key was configured. The article reports that the Python packages activated through their initialization files without requiring an API key.
- The payloads harvested environment variables whose names contained KEY, SECRET, TOKEN, PASS, AUTH, or API, truncating each captured value to 100 characters.
- The payloads sent stolen secrets and host fingerprints as JSON over outbound HTTPS to a C2 endpoint.
- Defensive Notes
- Rotate all secrets on machines that imported or executed the malicious packages, especially environment variables matching the payload's harvesting filters.
- Search dependency trees for the listed malicious packages and block them at the registry proxy level.
- Hunt for unusual outbound HTTPS connections from build and CI hosts to the tunnel-hosting infrastructure identified in the indicators.
- Audit CI logs for payment API key usage alongside the listed malicious packages.
- The JavaScript payload skipped exfiltration on systems with fewer than two CPU cores or sandbox-related hostname or username strings; the Python example checked hostname strings.
- The article reports that obfuscation keys differed across package versions, limiting detection based on a reused key.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | caliber-spinner-finishing[.]ngrok-free[.]dev | C2 hostname explicitly listed under network indicators. |
| SHA256 | 1314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 1bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bc | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 1bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 1d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 1df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501b | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 2303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 2b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 2bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bd | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 2edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213d | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 39371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 3a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 4a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 50cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 5242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 52a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 5c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 5cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528e | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 61b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 67e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 67eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 6dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 6e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 8a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188b | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 8a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 9727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 9e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | 9fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cf | Malicious index.js artifact listed in the file indicators. |
| SHA256 | a0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120c | Malicious index.js artifact listed in the file indicators. |
| SHA256 | a677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | af66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | b04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785 | Malicious __init__.py artifact listed in the file indicators. |
| SHA256 | b157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | b29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aad | Malicious index.js artifact listed in the file indicators. |
| SHA256 | b2ea8d69f6792a87327ffde2ee4551bb6b99617f53e1ba71bf9a70f45dbc57ea | Malicious index.js artifact listed in the file indicators. |
| SHA256 | c2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1 | Malicious __init__.py artifact listed in the file indicators. |
| SHA256 | c2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023de | Malicious index.js artifact listed in the file indicators. |
| SHA256 | c2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | c51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | c6af37a6739f0d919ab7049caf3a85831cab44bdbea27e0d9de7adec80334e2b | Malicious __init__.py artifact listed in the file indicators. |
| SHA256 | c8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | cd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723ad | Malicious index.js artifact listed in the file indicators. |
| SHA256 | ce09810adca70ebec87bc455380ef629ceaa2a0d926149d9115604060167682c | Malicious index.js artifact listed in the file indicators. |
| SHA256 | d1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | d4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | dabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5 | Malicious __init__.py artifact listed in the file indicators. |
| SHA256 | e076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | eae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bcc | Malicious index.js artifact listed in the file indicators. |
| SHA256 | f43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418 | Malicious index.js artifact listed in the file indicators. |
| SHA256 | f7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35ca | Malicious index.js artifact listed in the file indicators. |
| URL | hxxps[:]//caliber-spinner-finishing[.]ngrok-free[.]dev/ | Credential-exfiltration endpoint explicitly listed under network indicators. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe C2 hostname was concealed with Base64, XOR, character shifting, and reversal; obfuscation keys varied across versions and packages.T1033 · System Owner/User DiscoveryThe payload obtained the current username for sandbox checks and included it in the exfiltrated victim fingerprint.T1036 · MasqueradingThe packages impersonated payment SDKs, exposing fake client methods and legitimate-looking endpoint strings while returning fabricated success responses.T1041 · Exfiltration Over C2 ChannelThe payload uploaded harvested environment secrets, API key fragments, and host fingerprints to its C2 endpoint.T1071.001 · Web ProtocolsThe malicious packages communicated with their C2 endpoint using HTTPS requests on port 443 with JSON bodies.T1082 · System Information DiscoveryThe payload inspected CPU count and collected the victim hostname for sandbox checks and exfiltrated host fingerprints.T1140 · Deobfuscate/Decode Files or InformationThe payload decoded and transformed embedded strings at runtime to reconstruct its C2 hostname.T1195.001 · Compromise Software Dependencies and Development ToolsThe attacker published malicious payment SDK packages on npm and PyPI to reach developers through software dependencies.T1497.001 · System ChecksThe JavaScript payload checked CPU count and sandbox-related hostname or username strings before exfiltration; the Python example checked hostname strings.T1552 · Unsecured CredentialsThe payload harvested API keys, passwords, secrets, and tokens directly from matching environment variables on developer machines and CI runners.
Malware
Vendors
Products
Netellerpublished nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and Neteller payment applications. Ultimately, the packages perform credential and token theft, exfiltrating stolennpmSocket’s AI scanner detected a cluster of npm and PyPI malware published on July 7, 2026. The 17 packages, published nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and NetellerPaySafe2026. The 17 packages, published nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and Neteller payment applications. Ultimately, the packages perform credential and token theft,PyPISocket’s AI scanner detected a cluster of npm and PyPI malware published on July 7, 2026. The 17 packages, published nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and NetellerSkrillThe 17 packages, published nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and Neteller payment applications. Ultimately, the packages perform credential and token theft,