Cybersecurity researchers have identified a malicious npm package named nodejs-smtp, which mimics the legitimate library nodemailer, to stealthily inject harmful code into cryptocurrency wallet applications like Atomic and Exodus on Windows systems. This package has attracted 347 downloads due to its deceptive design, including identical styling and README descriptions.
Want More Context? 🔎
