Deceptive npm Package Aims at Atomic Wallet, Exodus Users by Interchanging Crypto Addresses
Perpetrators persist in uploading deceptive packages to the npm registry to manipulate existing local copies of authentic libraries to run harmful code in a more clandestine effort to orchestrate a software supply chain breach. The recently uncovered package, called pdf-to-office, disguises itself as a tool for transforming PDF files into Microsoft Word documents. However, in
