A malicious npm campaign is targeting #Ethereum developers by impersonating @hardhathq plugins and the @nomicfoundation. Socket researchers have identified 20 malicious packages that exfiltrate sensitive data like private keys and mnemonics.
https://socket.dev/blog/malicious-npm-campaign-targets-ethereum-developers #JavaScript