Ars Technica reports that decentralized finance cryptocurrency exchange dYdX had its developers' and backend systems' wallet credentials stolen by multiple malicious open-source packages on the npm and PyPI repositories.Included in the illicit @dydxprotocol/v4-client-js npm package versions 3.4.1, 1.22.1, 1.15.2, and 1.0.31 was a malignant function that allowed seed phrase and device fingerprint exfiltration, as well as stolen credential correlation for victim tracking, according to Socket researchers. On the other hand, the dydx-v4-client PyPI package version 1.1.5post1 added a remote access trojan on top of the credential-stealing function to facilitate Python code execution in an isolated subprocess and the subsequent pilfering of API credentials, SSH keys, source codes, and other sensitive files, deployment of persistent backdoors, and lateral network movement."Viewed alongside the 2022 npm supply chain compromise and the 2024 DNS hijacking incident, this [latest] attack highlights a persistent pattern of adversaries targeting dYdX-related assets through trusted distribution channels," said researchers.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




