Fake Paysafe, Skrill, and Neteller SDK packages on npm and PyPI stole developer credentials and API keys

Attackers uploaded fake software packages for Paysafe, Skrill, and Neteller to npm and PyPI, putting developers and any systems that ran them at risk of credential theft. Socket identified 17 malicious packages: 13 on npm with versions 1.0.0 through 1.0.3 and 4 on PyPI at version 1.0.0. The packages imitated legitimate payment software development kits, exposed expected APIs, returned fake success responses, and exfiltrated Paysafe API keys, AWS keys, GitHub tokens, npm tokens, passwords, and host metadata to attacker infrastructure on AWS.
Why it matters: Developers, payment integrations, and continuous integration systems may have had secrets stolen just by importing or running these packages. Organizations that installed them should remove the packages, audit dependency trees and build logs, and rotate exposed credentials immediately.

Sources

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Bill Toulas 2026.07.08 100% relevant
This article establishes a distinct cross-ecosystem package-repository compromise targeting developers who use payment SDKs, with a specific package set, credential-theft behavior, and affected brands not covered by an existing tracked story.
← Back to all stories