Cyfirma multi-stage crypto-wallet campaign: moralis-sdk, ethers-jss, coinbase-wallet-utils, plus the `ethcompat` ethereum-C2 cluster
Cyfirma Research disclosed an 11-package npm campaign targeting Web3 / blockchain developers across three clusters: a YouTube-page-gated postinstall trojan in moralis-sdk (2.7M+ downloads from the legitimate package name), the ethers-jss / coinbase-wallet-utils private-key sweepers (both yanked 2026-06-10), three long-lived typosquats (ganach, solidty, stelar-sdk, live since 2024), and the ethcompat 5-pack (hardhat-deploy-utils, web3-deploy-helper, defi-sdk-core, ethers-compat, ethereum-dev-utils) that AES-256-GCM-encrypts stolen creds and embeds them in Ethereum transactions to an attacker wallet.
Versions named here: 1.0.0