According to Microsoft Threat Intelligence, two malicious npm packages—utils-terminal@3.2.1 and logger-active@3.2.1—were discovered distributing a remote access trojan (RAT) designed to steal cryptocurrency wallet credentials, API keys, and other sensitive data from developers' systems.
The attackers routed stolen information through Hugging Face, a machine learning platform, to evade detection by making the activity appear less suspicious than direct command-and-control communications. The threat is particularly concerning for crypto developers, whose workstations often contain wallet private keys, seed phrase backups, and exchange credentials.