Fake Paysafe and Skrill SDKs on npm and PyPI Went After Developers' Secrets

A single attacker uploaded 17 lookalike payment packages that quietly stole API keys, cloud credentials and GitHub tokens from anyone who installed them.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: a developer's dark wooden desk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • A single attacker uploaded 17 fake payment packages to the npm and PyPI software libraries, first reported by BleepingComputer.
  • The packages impersonated official code kits for Paysafe and Skrill, including the Neteller wallet, all widely used in online payments.
  • Once installed, the code hunted for Paysafe API keys, AWS keys, GitHub tokens and npm tokens, then sent them to an attacker-controlled server.
  • Socket, the application security firm that spotted the campaign, says the stolen data was sent to a command server hosted on Amazon Web Services.
  • Any developer who installed one of the packages should rotate every secret on the affected machine immediately.

Someone with time on their hands went shopping in the developer aisle again.

Researchers at Socket, an application security firm, have flagged 17 malicious software packages uploaded to npm and PyPI, the two big public libraries where programmers grab ready-made code to plug into their apps. Npm serves the JavaScript world; PyPI serves Python. Both are, in effect, app stores for developers. Both keep getting used as delivery vans for credential theft. Socket has come up in our coverage before: this is the fourth time we've reported on their findings, starting with the Miasma campaign on 2 June 2026.

The packages all pretended to be official code kits, known as SDKs, for three real payment brands: Paysafe, Skrill and Neteller. Paysafe handles payments for e-commerce sites, gaming platforms, travel businesses and financial software providers. Skrill and Neteller are digital wallets popular with online betting platforms, cryptocurrency exchanges and foreign-exchange traders. If you build software for any of those industries, installing a Paysafe SDK is a normal Tuesday.

That's exactly what the attacker was counting on.

What did the fake packages actually do?

They stole secrets. The code looked and behaved like a real payment kit, returning fake success messages so a developer testing it would think everything was working. Behind the scenes it rummaged through the machine for anything valuable: Paysafe API keys, AWS keys, GitHub tokens, npm tokens, plus the machine's hostname and username. All of it was quietly shipped to a server the attacker had set up on Amazon's cloud.

An API key is basically a password that lets one piece of software talk to another. Steal a company's Paysafe API key and you can start impersonating that company to Paysafe. Steal its AWS keys and you may be able to read databases or drain a cloud account entirely.

The npm versions were slightly more patient, phoning home only if a Paysafe API key was actually present. The PyPI versions were greedier: they ran their theft routine the moment they were loaded, no key required.

Both versions included light checks to avoid running inside a researcher's test environment. Fewer than two processor cores, or a hostname that looked like a sandbox, and the malware went quiet. Nothing fancy. Enough to slow down casual analysis.

The 13 npm packages published four malicious versions, 1.0.0 through 1.0.3. The four PyPI packages published one version each, 1.0.0.

Should ordinary customers of Paysafe or Skrill be worried?

Not directly. The attack targeted developers, not end users, and there's no sign the payment services themselves were compromised. The victims are the software teams who might have pulled a poisoned package into a build.

Watch your statements and treat any unexpected email about your account as suspect until proven otherwise.

For developers, Socket's guidance is blunt. Check your dependency lists against the 17 package names. If any touched your machine or build pipeline, rotate every secret on that machine, then search your continuous integration logs, the automated system that builds and tests code on each update, for the string PAYSAFE_API_KEY next to any of the listed package names. Registry proxies can be told to refuse these packages outright.

The full package list is in Socket's writeup; the names all follow the obvious pattern: paysafe-checkout, paysafe-vault, skrill-sdk, neteller and so on.

Socket's researchers think whoever ran this campaign is competent enough to try again under different names. That cross-ecosystem reach, hitting npm and PyPI in the same push, is what makes this harder to catch than a single-registry campaign. Typosquatting on package registries isn't a new trick. It's the developer equivalent of a fake login page: cheap, repeatable, and it only has to work once.

© 2026 Threat Vectr