{"id":347007,"date":"2025-09-09T09:25:00","date_gmt":"2025-09-09T16:25:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=395412"},"modified":"2025-09-09T11:36:56","modified_gmt":"2025-09-09T18:36:56","slug":"if-you-have-cryptocurrency-wallets-a-way-has-been-discovered-in-which-they-could-steal-your-credentials-from-them","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/if-you-have-cryptocurrency-wallets-a-way-has-been-discovered-in-which-they-could-steal-your-credentials-from-them\/","title":{"rendered":"If you have cryptocurrency wallets, a way has been discovered in which they could steal your credentials from them"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Recently, four malicious packages have been discovered in the npm registry that have the ability to steal cryptocurrency wallet credentials from Ethereum developers. <strong>These packages, uploaded by a user calling themselves &#8216;flashbotts&#8217;, impersonate legitimate cryptocurrency utilities<\/strong> and the Flashbots infrastructure, while exfiltrating private keys and seed phrases to a Telegram bot controlled by the attackers.<\/p>\n\n\n<h2 class=\"wp-block-heading\">A tremendously serious security problem<\/h2>\n\n\n<p class=\"wp-block-paragraph\">Among the identified packages, &#8216;@flashbotts\/ethers-provider-bundle&#8217; stands out, designed to hide malicious operations behind seemingly innocuous functions.<strong> This package incorporates functionality that redirects unsigned transactions to a wallet controlled by the attacker and also captures metadata from pre-signed transactions<\/strong>. Even more alarming, this type of deceptive handling could allow criminals to take full control of the victims&#8217; accounts.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The attacks are designed to exploit the trust placed in Flashbots, an entity widely recognized for its role in mitigating the adverse effects of Maximal Extractable Value (MEV) on the Ethereum network. <strong>This context of trust facilitates the inadvertent adoption of these malicious packages by developers seeking legitimate tools for their projects<\/strong>.<\/p>\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Ethereum: the World Computer\" width=\"840\" height=\"473\" src=\"https:\/\/www.youtube.com\/embed\/j23HnORQXvs?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n<p class=\"wp-block-paragraph\">Investigations indicate that malicious packages not only operate under the guise of seemingly benign functions,<strong> but can also be activated in the code of projects without the knowledge of their developers<\/strong>. The inclusion of comments in Vietnamese in the code suggests that the attackers may be Vietnamese speakers.<\/p>\n\n\n<p class=\"wp-block-paragraph\">According to experts, the existence of these malicious packages turns Web3 development into a direct conduit to bots controlled by criminals,<strong> which poses a considerable risk to the security of cryptocurrency investments<\/strong>. The appropriation of private keys in this environment can lead to irreversible theft of funds, raising serious concerns for the Ethereum developer and user community.<\/p>\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Avast Free Antivirus\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/2d9f9134-96d0-11e6-bf8f-00163ec9f5fa\/1408299994\/avast-Avast_Symbol_V2_Positive_Orange_256x256.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Avast Free Antivirus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/avast.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/avast.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Recently, four malicious packages have been discovered in the npm registry that have the ability to steal cryptocurrency wallet credentials from Ethereum developers. These packages, uploaded by a user calling themselves &#8216;flashbotts&#8217;, masquerade as legitimate cryptographic utilities and the Flashbots infrastructure, while exfiltrating private keys and seed phrases to a Telegram bot controlled by the attackers. A tremendously serious security issue Among the identified packages, &#8216; @flashbotts\/ethers-provider-bundle&#8217; stands out, designed to hide malicious operations behind seemingly innocuous functions. This package incorporates functionality that redirects unsigned transactions to a [&#8230;]<\/p>\n","protected":false},"author":9318,"featured_media":347008,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[15834,5605,5816,15835,2216,1472,15836,15837,3808,10884],"usertag":[],"vertical":[],"content-category":[7176],"class_list":["post-347007","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-billeteras-de-criptomonedas","tag-ciberseguridad","tag-criptomonedas","tag-ethereum","tag-hackers","tag-hacking","tag-mex","tag-red-etherum","tag-seguridad","tag-web3","content-category-seguridad-privacidad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/347007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9318"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=347007"}],"version-history":[{"count":2,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/347007\/revisions"}],"predecessor-version":[{"id":347012,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/347007\/revisions\/347012"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/347008"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=347007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=347007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=347007"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=347007"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=347007"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=347007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}