Two spoofed versions of the Web3.js library were pushed out to capture private keys and send them to a hardcoded address.