Malicious npm package targets Node.js apps via SMTP abuse—developers must audit dependencies and monitor for covert exfiltration. 📦📤 #SupplyChainRisk #NodeSecurity

https://thehackernews.com/2025/09/malicious-npm-package-nodejs-smtp.html

Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets

Malicious npm package nodejs-smtp, downloaded 347 times since April 2025, hijacks Atomic and Exodus wallets.

The Hacker News