October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Malicious npm Packages Targeted Cryptocurrency and PayPal Users: What to Check Now

Separate PayPal-themed and crypto-wallet npm campaigns used installation code to exfiltrate data or redirect transactions. Here are the indicators, recovery steps and prevention controls.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Two separate malicious npm campaigns reported in 2025 targeted developers and users of financial software. PayPal-themed packages ran installation scripts that collected system information and sent it to attacker-controlled servers. A package called pdf-to-office modified locally installed Atomic Wallet and Exodus Wallet files so cryptocurrency transactions could be redirected.

Neither report establishes a breach of PayPal, Atomic Wallet, Exodus, or npm infrastructure. Exposure required installing an implicated package on a relevant computer. If that may have happened, deleting the package is not enough: investigate the host, rotate credentials, and— for a potentially modified wallet—move funds from a known-clean device and reinstall the wallet software.

What happened

Attackers abused npm’s trusted distribution channel by publishing packages with plausible names, then using code that executed during installation or changed files outside the project directory. The two campaigns should not be treated as one incident or automatically attributed to the same actor.

Campaign Packages Observed behavior Primary risk
PayPal-themed campaign oauth2-paypal, buttonfactoryserv-paypal, compliancereadserv-paypal, bankingbundleserv, and tommyboytesting versions npm preinstall execution, system reconnaissance and data exfiltration Credential attacks, reconnaissance and follow-on fraud
Wallet campaign pdf-to-office Local modification of Atomic Wallet and Exodus Wallet files Cryptocurrency sent to an attacker’s address

Fortinet said the PayPal-themed packages were created between March 5 and March 14, 2025, and associated them with the aliases tommyboy_h1 and tommyboy_h2. ReversingLabs detected pdf-to-office shortly after an update published April 1, 2025. These are reported 2025 campaigns, not proof that the activity remains active in 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How the PayPal-themed packages worked

The packages used PayPal-related branding to appear useful to developers. Their npm lifecycle configuration caused a shell script to run automatically through a preinstall hook. Fortinet observed collection of the current username, hostname, working directory and directory paths. The data was obfuscated or encoded and sent to an external server using a dynamically generated URL. Fortinet classified detected files as Bash/TommyBoy.A!tr.

This evidence demonstrates reconnaissance and exfiltration, not a confirmed theft of PayPal passwords. The information could help attackers target PayPal accounts or other systems later. Fortinet’s technical report contains the authoritative package list, versions and SHA-256 indicators: Fortinet’s analysis.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How pdf-to-office tampered with wallets

The package presented itself as a PDF-to-Microsoft-Office conversion library but contained obfuscated JavaScript. It searched for locally installed Atomic Wallet and Exodus Wallet applications, modified their files, and changed wallet behavior so an intended recipient address could be replaced with an attacker-controlled address during an outgoing transaction. It also sent a ZIP archive to remote infrastructure, indicating possible additional collection.

The dangerous persistence point is outside the npm project: modified wallet files could remain after pdf-to-office or its node_modules directory was deleted. ReversingLabs recommended completely removing the affected wallet application and reinstalling it. It reported that the official Atomic Wallet and Exodus installers were not compromised in this campaign. See the ReversingLabs report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Versions and hashes to investigate

For the wallet campaign, compare package name, version and SHA-1—not just the name in a dependency file—with the original ReversingLabs indicators:

Package Version SHA-1
pdf-to-office 1.0.0 92ae8c8317da6dd1660c3decb55be74b1a41f3df
pdf-to-office 1.0.1 7172583d31d7b79737b21b0d6f76cf179c60f728
pdf-to-office 1.0.2 e8ad87a866b6677ef96de30bd93a455ce7247ffc
pdf-to-office 1.0.3 59384e801dcf0299e0e704434c00b0da65550c01
pdf-to-office 1.1.2 Later version reported after the original package was removed; verify against the source report

Fortinet lists the affected PayPal-themed versions, including buttonfactoryserv-paypal 3.50.0 and 3.99.0; oauth2-paypal 0.6.0, 1.6.0 and 7.5.0; compliancereadserv-paypal 2.1.0; bankingbundleserv 1.20.0; and tommyboytesting 1.0.1, 1.0.2 and 1.0.5 through 1.0.12. Treat that page as the authoritative package and hash reference rather than assuming every similarly named release was malicious.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What to do if a PayPal-themed package was installed

  1. Stop sensitive use of the computer. Do not sign in to PayPal, email, npm, GitHub, cloud consoles or exchanges from it until it has been examined.
  2. Preserve evidence. Keep package-lock.json or npm-shrinkwrap.json, npm logs, shell history, endpoint and DNS logs, and package tarballs. Work from copies when following an approved forensic process.
  3. Establish exposure. Check dependency history and exact versions; a current node_modules directory may no longer contain a package that was previously installed.
  4. Scan and hunt. Use endpoint-malware tools, review lifecycle scripts and investigate unexpected processes, files, scheduled tasks, shell-profile changes and outbound connections.
  5. Rotate and revoke secrets from a clean device. Prioritize PayPal, email, npm, GitHub, cloud accounts, SSH keys, CI/CD tokens, exchanges and wallets. Revoke sessions, API tokens and deploy keys, then issue replacements with least privilege.
  6. Review PayPal. Check login history, payments, funding sources, recovery details and unfamiliar devices, and report suspicious activity to PayPal.
  7. Tell your security team. A developer workstation may have had access to production credentials or source repositories even if no PayPal account was used on it.

These steps follow Fortinet’s guidance to remove suspicious packages, change compromised credentials, inspect network activity and scan for additional threats: Fortinet.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if Atomic Wallet or Exodus was present

  1. Do not send another transaction from the affected wallet. Treat it as compromised until the host and application are clean.
  2. Use a known-clean device to secure assets. If possible, move funds to a newly secured wallet, verifying the destination address on a separate trusted display before confirming.
  3. Preserve records. Save transaction IDs, timestamps and suspicious destination addresses.
  4. Remove the wallet application completely. Deleting only the npm package or project directory may leave modified wallet files behind.
  5. Reinstall from the vendor’s official channel. Replace the application files, not merely the data directory, and do not reinstall onto a host that may still be compromised.
  6. Review all transactions since the suspected installation date. Contact the wallet provider, exchange or relevant financial service if funds were redirected.

For high-value holdings, use a known-clean device or hardware wallet and assume that secrets entered on the old host may be exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Investigating npm exposure

Run these checks in an approved incident-response workflow, preferably against a preserved copy of the project:

npm ls --all
npm explain <package-name>
npm audit
git diff -- package-lock.json npm-shrinkwrap.json
grep -R '"preinstall"|"install"|"postinstall"' package.json node_modules/*/package.json
  • npm audit reports known vulnerabilities; it is not a guarantee that a package is free of malware.
  • A lockfile records what was selected, but a deliberately pinned malicious package remains malicious.
  • Searching only the current node_modules tree can miss a removed dependency. Check Git history, CI logs, caches and artifact repositories.
  • Windows users should use equivalent PowerShell, event-log and endpoint-detection searches.
  • Do not delete evidence before collecting timestamps, hashes and relevant logs.

Controls that reduce future supply-chain risk

  • Review ownership, repository links, publication history, release cadence and sudden maintainer changes before adding a dependency.
  • Inspect package.json for preinstall, install and postinstall scripts, and require peer review for additions and updates.
  • Commit lockfiles, review dependency diffs and use npm ci for reproducible CI installs.
  • Disable lifecycle scripts where the build does not require them, documenting the trade-off: native modules and legitimate setup tasks may fail.
  • Install in isolated, minimally privileged environments. Keep long-lived cloud, npm, GitHub and wallet credentials out of build jobs.
  • Use short-lived, least-privilege tokens; monitor outbound connections from installation and build processes.
  • Generate software bills of materials, scan packages before admitting them to internal repositories, and use provenance or signature verification where available.
  • Alert on ownership transfers, unusual release behavior and newly introduced install scripts.

What remains unknown

The cited reports do not establish a victim count, a confirmed amount of cryptocurrency stolen, a verified list of compromised PayPal accounts, or successful theft from every modified wallet. They also do not show that PayPal, Atomic Wallet, Exodus or their official distribution servers were breached. The PayPal campaign was associated with publisher aliases, not a verified real-world identity, and there is no evidence here that the two campaigns had the same author.

Package-registry removal can stop new downloads, but it cannot repair an already modified application, revoke stolen credentials or recover cryptocurrency. The appropriate response depends on what was installed and what secrets or assets the machine could access.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.