Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Reported 07 Jul 2026 by otx · Severity: medium
Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sop