P.01Cybersecurity/Supply Chain Security··5 min read
Fake Paysafe, Skrill, and Neteller SDKs Hit npm and PyPI in the Same Hour
Seventeen packages published July 7, 2026 impersonated real payment SDKs, returned fake success responses, and quietly exfiltrated API keys and cloud credentials. Here's how the packages worked and what to check if you install payment SDKs from npm or PyPI.
Supply Chain AttacknpmPyPI
Read