Netherеum.All NuGet typosquat wallet-stealer
Malware Activity
Summary
Hide ▲
Show ▼
The Netherеum.All NuGet package was exposed as a malicious supply-chain implant that can steal cryptocurrency wallet secrets from users of Nethereum. Its payload decodes a hidden C2 endpoint and exfiltrates mnemonic phrases, private keys, and keystore data. The package was uploaded on October 16, 2025, removed four days later, and relied on a Cyrillic homoglyph trick to look legitimate.
Related Happenings
Telnyx package WAV-hidden credential-stealing malware
Malware Activity
H score29
First: 27.03.2026 23:13
Last: 27.03.2026 23:13
Sources 1
About this happening:
The malicious Telnyx package releases 4.87.1 and 4.87.2 delivered credential-stealing malware to imported systems, putting Linux, macOS, and Windows environmen...
Telnyx package WAV-hidden credential-stealing malware
Malware ActivityAbout this happening: The malicious Telnyx package releases 4.87.1 and 4.87.2 delivered credential-stealing malware to imported systems, putting Linux, macOS, and Windows environmen...
Telnyx package hit by network compromise
Incident
H score19
First: 27.03.2026 23:13
Last: 27.03.2026 23:13
Sources 1
About this happening:
The Telnyx package on PyPI was compromised, and malicious releases began executing at import, putting downstream developers at risk of secret theft. The bad uploads in...
Telnyx package hit by network compromise
IncidentAbout this happening: The Telnyx package on PyPI was compromised, and malicious releases began executing at import, putting downstream developers at risk of secret theft. The bad uploads in...
Ghost campaign malicious npm supply-chain operation
Campaign
H score38
First: 24.03.2026 16:30
Last: 24.03.2026 16:30
Sources 1
About this happening:
A malicious npm supply-chain campaign dubbed "Ghost campaign" is using fake installation logs to conceal malware delivery, increasing the chance that package installer...
Ghost campaign malicious npm supply-chain operation
CampaignAbout this happening: A malicious npm supply-chain campaign dubbed "Ghost campaign" is using fake installation logs to conceal malware delivery, increasing the chance that package installer...
TeamPCP Cloud stealer credential-stealing operation
Malware Activity
H score53
First: 24.03.2026 11:29
Last: 24.03.2026 11:29
Sources 1
About this happening:
TeamPCP Cloud stealer was used in poisoned GitHub Actions and extension payloads that hit Checkmarx workflows, expanding a supply-chain credential-theft operation acro...
TeamPCP Cloud stealer credential-stealing operation
Malware ActivityAbout this happening: TeamPCP Cloud stealer was used in poisoned GitHub Actions and extension payloads that hit Checkmarx workflows, expanding a supply-chain credential-theft operation acro...
Latest development: 23.04.2026 22:21
Threat actors published a malicious @bitwarden/cli version 2026.4.0 on April 22, 2026, likely through a compromised GitHub Action in Bitwarden's CI/CD pipeline, and used bw_setup.js and bw1.js to download Bun, steal developer secrets, and exfiltrate AES-256-GCM-encrypted data through public GitHub repositories under victim accounts.
CanisterWorm self-propagation across npm packages
Malware Activity
H score23
First: 21.03.2026 09:28
Last: 21.03.2026 09:28
Sources 1
About this happening:
A self-propagating npm supply-chain worm tracked as CanisterSprawl is abusing stolen developer npm tokens to spread through compromised packages. Socket and Step...
CanisterWorm self-propagation across npm packages
Malware ActivityAbout this happening: A self-propagating npm supply-chain worm tracked as CanisterSprawl is abusing stolen developer npm tokens to spread through compromised packages. Socket and Step...
Timeline
-
22.10.2025 14:43 1 articles · 8mo ago
Typosquatted Netherеum.All uploaded to NuGet
Untyped PhaseA user named `nethereumgroup` uploaded the malicious NuGet package `Netherеum.All`, which impersonated Nethereum by swapping the last Latin `e` with a Cyrillic homoglyph to mislead developers into installing a wallet-stealing typosquat.
Show sources
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43
-
22.10.2025 14:43 1 articles · 8mo ago
NuGet removes Netherеum.All after policy violation
Legal Policy Action UpdateNuGet security staff removed `Netherеum.All` after it violated the service's Terms of Use, ending distribution of the malicious package that targeted Nethereum users' cryptocurrency wallet secrets.
Show sources
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43
-
22.10.2025 14:43 2 articles · 8mo ago
Researchers disclose NuGet supply chain wallet-stealer
Initial DisclosureSecurity researchers described a NuGet supply chain attack against Nethereum users in which `Netherеum.All` decoded a command-and-control endpoint at `solananetworkinstance[.]info/api/gads` and exfiltrated mnemonic phrases, private keys, and keystore data.
Show sources
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43