TechFlow news, on June 3, the Socket security research team discovered four malicious npm packages targeting wallet users on Binance Smart Chain (BSC) and Ethereum. The packages are pancake_uniswap_validators_utils_snipe (350 downloads), pancakeswap-oracle-prediction (445 downloads), ethereum-smart-contract (305 downloads), and env-process (1,054 downloads), with a total download count exceeding 2,100.
The attackers use obfuscated JavaScript code to calculate a percentage of the victim wallet's balance and attempt to transfer up to 85% of the assets to wallet addresses under their control.




