Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
A coordinated supply-chain campaign published 17 typosquatted npm and PyPI packages mimicking PaySafe, Skrill, and Neteller payment SDKs. The packages implement a fake SDK facade that harvests environment variables containing credentials and tokens, then exfiltrates them over HTTPS to an ngrok-based C2 server. The malware includes sandbox evasion logic and multi-layer C2 domain obfuscation to hinder analysis.
- domaincaliber-spinner-finishing[.]ngrok-free[.]devC2 domain used for exfiltrating stolen environment variables and credentials; decoded from XOR + char-shift + reverse obfuscation
- npm_packagepaysafe-apiMalicious npm package typosquatting Paysafe API SDK; part of 13-package npm campaign
- npm_packagepaysafe-nodePrimary malicious npm package analyzed in the article; exports fake PaysafeClient that steals PAYSAFE_API_KEY and env vars
- npm_packageskrill-paymentsMalicious npm package typosquatting Skrill payment SDK; part of coordinated campaign
- pypi_packagepaysafe-apiMalicious PyPI package typosquatting Paysafe API SDK; part of 4-package PyPI campaign
- pypi_packagepaysafe-sdkPrimary malicious PyPI package analyzed; activates on import via __init__.py, universally exfiltrates env vars without API key gating
- sha2561314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23Malicious index.js from npm campaign variant
- sha2561bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bcMalicious index.js from npm campaign variant
- sha2561bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410Malicious index.js from npm campaign variant
- sha2561d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89Malicious index.js from npm campaign variant
- sha2561df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501bMalicious index.js from npm campaign variant
- sha2562303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7Malicious index.js from npm campaign variant
- sha2562b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982Malicious index.js from npm campaign variant
- sha2562bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bdMalicious index.js from npm campaign variant
- sha2562cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0edMalicious index.js from npm campaign variant
- sha2562edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213dMalicious index.js from npm campaign variant
- sha256313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14Malicious index.js from npm campaign variant
- sha256390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3Malicious index.js from npm campaign variant
- sha25639371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1Malicious index.js from npm campaign variant
- sha2563a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0Malicious index.js from npm campaign variant
- sha256447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5Malicious index.js from npm campaign variant
- sha2564a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0Malicious index.js from npm campaign variant
- sha25650cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048Malicious index.js from npm campaign variant
- sha2565242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23Malicious index.js from npm campaign variant
- sha25652a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405Malicious index.js from npm campaign variant
- sha2565c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85Malicious index.js from npm campaign variant
- sha2565cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9Malicious index.js from npm campaign variant
- sha256615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369Malicious index.js from npm campaign variant
- sha256616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528eMalicious index.js from npm campaign variant
- sha25661b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63Malicious index.js from npm campaign variant
- sha25667e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4Malicious index.js from npm campaign variant
- sha25667eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5Malicious index.js from npm campaign variant
- sha2566dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5Malicious index.js from npm campaign variant
- sha2566e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1Malicious index.js from npm campaign variant
- sha256727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697Malicious index.js from npm campaign variant
- sha2568a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188bMalicious index.js from npm campaign variant
- sha2568a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43Malicious index.js from npm campaign variant
- sha2569727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94Malicious index.js from npm campaign variant
- sha2569e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9Malicious index.js from npm campaign variant
- sha2569fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cfMalicious index.js from npm campaign variant
- sha256a0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120cMalicious index.js from npm campaign variant
- sha256a677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8Malicious index.js from npm campaign variant
- sha256af66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304Malicious index.js from npm campaign variant
- sha256b04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785Malicious __init__.py from PyPI campaign variant
- sha256b157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0Malicious index.js from npm campaign variant
- sha256b29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aadMalicious index.js from npm campaign variant
- sha256b2ea8d69f6792a87327ffde2ee4551bb6b99617f53e1ba71bf9a70f45dbc57eaSHA256 hash of malicious index.js variant from npm campaign; unique hash due to per-package obfuscation key rotation
- sha256c2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1Malicious __init__.py from PyPI campaign variant
- sha256c2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023deMalicious index.js from npm campaign variant
- sha256c2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151Malicious index.js from npm campaign variant
- sha256c51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987Malicious index.js from npm campaign variant
- sha256c6af37a6739f0d919ab7049caf3a85831cab44bdbea27e0d9de7adec80334e2bSHA256 hash of malicious __init__.py from PyPI package; contains equivalent credential theft and exfiltration logic
- sha256c8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83Malicious index.js from npm campaign variant
- sha256cd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723adMalicious index.js from npm campaign variant
- sha256ce09810adca70ebec87bc455380ef629ceaa2a0d926149d9115604060167682cSHA256 hash of malicious index.js from npm package; contains credential harvesting and C2 exfiltration logic
- sha256d1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2Malicious index.js from npm campaign variant
- sha256d4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25Malicious index.js from npm campaign variant
- sha256dabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5Malicious __init__.py from PyPI campaign variant
- sha256e076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9Malicious index.js from npm campaign variant
- sha256eae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bccMalicious index.js from npm campaign variant
- sha256f43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418Malicious index.js from npm campaign variant
- sha256f7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35caMalicious index.js from npm campaign variant
- urlhxxps://caliber-spinner-finishing[.]ngrok-free[.]dev:443/C2 URL receiving POST requests containing harvested credentials, hostname, username, and environment variables
Detection / Hunteropenrouter
What Happened
Attackers published fake versions of popular payment software development kits (tools programmers use to integrate payment features) on public package repositories for Node.js and Python. When developers downloaded and used these fake packages, the software secretly stole passwords, API keys, and other sensitive credentials stored on their computers or build systems, sending them to an attacker-controlled server. The attackers disguised their server address using encoding tricks and included checks to avoid detection by automated security analysis tools. Developers and organizations using PaySafe, Skrill, or Neteller SDKs should check their dependency lists for the affected package names, rotate any exposed secrets, and monitor for unusual outbound connections to ngrok domains.
Key Takeaways
- 17 malicious npm and PyPI packages typosquatted PaySafe, Skrill, and Neteller payment SDKs, published simultaneously on July 7, 2026
- Malware harvests environment variables matching KEY, SECRET, TOKEN, PASS, AUTH, or API patterns and exfiltrates them over HTTPS to an ngrok-based C2 domain
- Sandbox evasion checks CPU core count (<2), hostname, and username for strings like sandbox, analyzer, cuckoo, vmware, vbox before executing exfiltration
- C2 domain is obfuscated via XOR + character shift + reverse string operations to evade static analysis
- Threat actor used unique obfuscation keys per package/version to prevent signature tracking across the campaign
Affected Systems
- Node.js environments importing affected npm packages
- Python environments importing affected PyPI packages
- CI/CD runners and developer machines with environment-variable-based secrets
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Threat actor publishes 17 typosquatted npm and PyPI packages mimicking PaySafe, Skrill, and Neteller payment SDKs on public registries
- Execution: Developer installs malicious package; npm packages activate when PaysafeClient methods are called, PyPI packages activate on import via init.py
- Defense Evasion: Malware checks CPU core count, hostname, and username for sandbox indicators (sandbox, analyzer, cuckoo, vmware, vbox, virus, malware) and aborts exfiltration if detected; C2 domain obfuscated via XOR + char-shift + reverse encoding
- Collection: Malware harvests environment variables matching KEY, SECRET, TOKEN, PASS, AUTH, or API patterns, plus hostname, username, cwd, and first 10 chars of Paysafe API key
- Exfiltration: Stolen credentials and system fingerprint POSTed as JSON over HTTPS to ngrok-based C2 domain caliber-spinner-finishing.ngrok-free.dev
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article does not include formal detection rules but provides IOCs (SHA256 hashes, C2 domain, package names) and behavioral descriptions suitable for custom detection engineering.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can observe Node.js and Python processes making outbound HTTPS connections to ngrok domains, but the malicious logic executes within the runtime interpreter, limiting deep behavioral visibility. Process ancestry showing package install followed by outbound network calls may be visible. |
| Network Visibility | High | Outbound HTTPS POST to caliber-spinner-finishing.ngrok-free.dev is visible at the network layer. Ngrok-free.dev subdomain connections from build/CI hosts are anomalous and detectable via DNS resolution logs and proxy logs. |
| Detection Difficulty | Moderate | The C2 domain and package names are known IOCs, but the threat actor rotates obfuscation keys per version producing unique hashes. Behavioral detection (outbound ngrok connections from build hosts, env var harvesting patterns) requires correlation across log sources. Sandbox evasion means automated detonation may miss the exfiltration step. |
Required Log Sources
- DNS resolution logs
- Proxy/egress firewall logs (HTTPS outbound)
- Package manager install logs (npm, pip)
- CI/CD pipeline execution logs
- EDR process telemetry with network correlation
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for outbound HTTPS connections to *.ngrok-free.dev subdomains from CI/CD build runners or developer workstations, as this is unusual for legitimate payment SDK usage | DNS resolution logs, proxy logs, egress firewall logs | Exfiltration | Medium — legitimate developers may use ngrok for tunneling during local development, but ngrok-free.dev from build/CI hosts is suspicious |
| Consider hunting for Node.js or Python processes that enumerate environment variables matching KEY, SECRET, TOKEN, PASS, AUTH, or API patterns and subsequently make outbound network connections | EDR process telemetry, endpoint behavioral analytics | Collection | Medium — some legitimate tools read environment variables for configuration, but combining env var enumeration with outbound network calls is anomalous |
| Consider hunting for package installations matching the 17 known typosquatted package names across npm and PyPI registries in your environment | Package manager logs, registry proxy logs, dependency scanning tools | Initial Access | Low — these specific package names are identified as malicious and should not appear in legitimate dependency trees |
| Consider hunting for processes that check CPU core count or hostname/username for sandbox indicator strings before making network connections, as this indicates sandbox evasion behavior | EDR process telemetry, syscall monitoring | Defense Evasion | Low — this specific combination of system checks followed by network activity is strongly indicative of malware |
| Consider hunting for CI/CD pipeline executions where PAYSAFE_API_KEY environment variable is accessed in combination with installation of any paysafe, skrill, or neteller named packages | CI/CD execution logs, secret access logs, package install logs | Collection | Low — this correlation is highly specific to the campaign's targeting pattern |
Control Gaps
- Static signature-based AV may miss this malware due to per-package obfuscation key rotation producing unique hashes
- Sandbox-based detonation may fail to trigger exfiltration due to CPU count, hostname, and username checks
- Package registry allowlisting may not be in place, allowing installation of typosquatted packages
- Network-only detection may not catch the exfiltration if the ngrok domain is not previously flagged
Key Behavioral Indicators
- Node.js process (node) making outbound HTTPS POST to *.ngrok-free.dev subdomain
- Python process making outbound HTTPS POST to *.ngrok-free.dev subdomain
- Process reading environment variables matching KEY/SECRET/TOKEN/PASS/AUTH/API patterns before network connection
- Package install of paysafe-, skrill, or neteller named packages from npm or PyPI
- Outbound HTTPS to ngrok-free.dev from CI/CD build infrastructure
False Positive Assessment
Low — the specific package names, C2 domain, and SHA256 hashes are directly tied to the malicious campaign. Behavioral detections around ngrok-free.dev outbound connections from CI/CD hosts may produce some false positives from legitimate development tunneling use.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Search dependency trees and package manager caches for all 17 campaign package names and block them at registry proxy level if found.
- Consider rotating all secrets on any machine that imported or executed the affected packages, especially environment variables matching the harvest regex (KEY, SECRET, TOKEN, PASS, AUTH, API).
- If your EDR supports host isolation, consider isolating any machines confirmed to have installed or executed the affected packages pending forensic review.
- Consider auditing CI/CD pipeline logs for PAYSAFE_API_KEY usage combined with any of the listed package names to identify potential credential exposure.
Infrastructure Hardening
- Consider implementing package registry allowlisting or proxying to block known-malicious package names before they reach developer machines.
- Evaluate whether outbound connections to *.ngrok-free.dev from build/CI infrastructure can be blocked or alerted on, as this is unusual for legitimate payment SDK operations.
- Consider implementing secret scanning on environment variables in CI/CD pipelines to detect exposure of API keys and tokens.
- If applicable, evaluate using dependency scanning tools that integrate with Socket or similar supply-chain security platforms for automated malicious package detection.
User Protection
- Consider notifying developers who use PaySafe, Skrill, or Neteller SDKs to verify they are installing legitimate packages from official sources.
- Evaluate whether developer workstations and CI runners have endpoint protection capable of detecting anomalous outbound connections from Node.js or Python runtimes.
- Consider implementing developer guidance for verifying package authenticity before installation, including checking publisher identity and download counts.
Security Awareness
- Consider incorporating typosquatting attack scenarios into existing developer security training programs, emphasizing verification of package names before installation.
- Consider rolling out guidance to developers on the risks of environment variable exposure in CI/CD pipelines and the importance of secret management practices.
- If applicable, consider establishing a process for developers to report suspicious packages encountered in package registries.
MITRE ATT&CK Mapping
Resource Development
Credential Access
Command and Control
Exfiltration
Additional IOCs
- File Hashes:
8a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43(SHA256) - Malicious index.js from npm campaign variantc8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83(SHA256) - Malicious index.js from npm campaign variant9fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cf(SHA256) - Malicious index.js from npm campaign variant615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369(SHA256) - Malicious index.js from npm campaign variant6dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5(SHA256) - Malicious index.js from npm campaign variant4a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0(SHA256) - Malicious index.js from npm campaign variant9727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94(SHA256) - Malicious index.js from npm campaign variant313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14(SHA256) - Malicious index.js from npm campaign variant2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed(SHA256) - Malicious index.js from npm campaign varianta0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120c(SHA256) - Malicious index.js from npm campaign variant3a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0(SHA256) - Malicious index.js from npm campaign variant39371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1(SHA256) - Malicious index.js from npm campaign variantc51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987(SHA256) - Malicious index.js from npm campaign variant6e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1(SHA256) - Malicious index.js from npm campaign variantcd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723ad(SHA256) - Malicious index.js from npm campaign variant5c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85(SHA256) - Malicious index.js from npm campaign variant50cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048(SHA256) - Malicious index.js from npm campaign variant1bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bc(SHA256) - Malicious index.js from npm campaign variant1df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501b(SHA256) - Malicious index.js from npm campaign variantb29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aad(SHA256) - Malicious index.js from npm campaign variant9e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9(SHA256) - Malicious index.js from npm campaign variant67e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4(SHA256) - Malicious index.js from npm campaign variant1bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410(SHA256) - Malicious index.js from npm campaign variant2bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bd(SHA256) - Malicious index.js from npm campaign varianteae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bcc(SHA256) - Malicious index.js from npm campaign variantd4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25(SHA256) - Malicious index.js from npm campaign variant447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5(SHA256) - Malicious index.js from npm campaign variantf43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418(SHA256) - Malicious index.js from npm campaign variant1314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23(SHA256) - Malicious index.js from npm campaign variantaf66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304(SHA256) - Malicious index.js from npm campaign variantb157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0(SHA256) - Malicious index.js from npm campaign variant2303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7(SHA256) - Malicious index.js from npm campaign variant5242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23(SHA256) - Malicious index.js from npm campaign variant1d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89(SHA256) - Malicious index.js from npm campaign variantc2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151(SHA256) - Malicious index.js from npm campaign variant390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3(SHA256) - Malicious index.js from npm campaign variantf7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35ca(SHA256) - Malicious index.js from npm campaign variant2b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982(SHA256) - Malicious index.js from npm campaign variant2edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213d(SHA256) - Malicious index.js from npm campaign variant727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697(SHA256) - Malicious index.js from npm campaign variant8a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188b(SHA256) - Malicious index.js from npm campaign variant67eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5(SHA256) - Malicious index.js from npm campaign variant616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528e(SHA256) - Malicious index.js from npm campaign variant52a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405(SHA256) - Malicious index.js from npm campaign variantd1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2(SHA256) - Malicious index.js from npm campaign varianta677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8(SHA256) - Malicious index.js from npm campaign variante076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9(SHA256) - Malicious index.js from npm campaign variantc2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023de(SHA256) - Malicious index.js from npm campaign variant5cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9(SHA256) - Malicious index.js from npm campaign variant61b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63(SHA256) - Malicious index.js from npm campaign variantb04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785(SHA256) - Malicious init.py from PyPI campaign variantdabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5(SHA256) - Malicious init.py from PyPI campaign variantc2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1(SHA256) - Malicious init.py from PyPI campaign variant
- Other:
paysafe-checkout- Malicious npm package typosquatting Paysafe checkout SDKpaysafe-vault- Malicious npm package typosquatting Paysafe vault SDKneteller- Malicious npm package typosquatting Neteller SDKpaysafe-js- Malicious npm package typosquatting Paysafe JS SDKpaysafe-cards- Malicious npm package typosquatting Paysafe cards SDKpaysafe-fraud- Malicious npm package typosquatting Paysafe fraud detection SDKpaysafe-kyc- Malicious npm package typosquatting Paysafe KYC SDKskrill- Malicious npm package typosquatting Skrill SDKskrill-sdk- Malicious npm package typosquatting Skrill SDKpaysafe-payments- Malicious npm package typosquatting Paysafe payments SDKpaysafe-kyc- Malicious PyPI package typosquatting Paysafe KYC SDKpaysafe-payments- Malicious PyPI package typosquatting Paysafe payments SDK