HP Wolf Security, HP's threat research team, has released a report stating that a malware named Needle Stealer, disguised as an AI crypto trading assistant, has been using Microsoft's legitimate signed software to bypass security checks. It replaces seven browser-based crypto wallet extensions, including Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper, turning the familiar wallet interface into a credential trap to steal user login information. The report, published on September 17, is based on threats observed between April and June 2026.