Supply chain

Cryptowallet credential-stealing dYdX packages identified

Crypto Trading theme with blurred city abstract lights background

Ars Technica reports that decentralized finance cryptocurrency exchange dYdX had its developers' and backend systems' wallet credentials stolen by multiple malicious open-source packages on the npm and PyPI repositories.

Included in the illicit @dydxprotocol/v4-client-js npm package versions 3.4.1, 1.22.1, 1.15.2, and 1.0.31 was a malignant function that allowed seed phrase and device fingerprint exfiltration, as well as stolen credential correlation for victim tracking, according to Socket researchers. On the other hand, the dydx-v4-client PyPI package version 1.1.5post1 added a remote access trojan on top of the credential-stealing function to facilitate Python code execution in an isolated subprocess and the subsequent pilfering of API credentials, SSH keys, source codes, and other sensitive files, deployment of persistent backdoors, and lateral network movement.

"Viewed alongside the 2022 npm supply chain compromise and the 2024 DNS hijacking incident, this [latest] attack highlights a persistent pattern of adversaries targeting dYdX-related assets through trusted distribution channels," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds