Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps

Reported 07 Jul 2026 by otx · Severity: medium

Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sop