Supply chain attacks affect PyPI/npm/crates.io, with over 34 malicious packages targeting cryptocurrency and AI developers
According to Slow Fog's disclosure, the security agency MistEye detected a cross-registry supply chain attack incident, where attackers targeted developers in the fields of cryptocurrency, DeFi, Solana, Sui/Move, and AI by publishing malicious packages on npm, PyPI, and crates.io. This attack activity includes more than 34 malicious packages and over 384 related versions. The attackers may steal cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and developers' confidential information.
Some of the malicious payloads also attempted to achieve persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH. Developers are advised to immediately remove the affected packages, isolate the affected systems, retain logs, rotate exposed credentials, rebuild CI environments and developer machines from clean images, and review GitHub, cloud services, SSH, and wallet activity logs.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

New Jersey Seeks Supreme Court Review of Kalshi Sports Betting Contracts Case

Wonderful Completes $550 Million Series C Financing, Valuation Reaches $5 Billion

Ribas Hotels Group Invests 150 Million UAH in Hotel on Karolino-Buhaz Spit

Hungary to Introduce Wealth Tax, Expected Revenue of $1.86 Billion

Securitize Partners with Socios to Launch Sports Equity Tokenization Program

Tether Releases Open Source AI Translation Models Supporting African and European Languages

Argentine President Milei's Social Media Influence Drops by 72%

State Geological Service Files Six Lawsuits to Terminate Subsoil Use Permits

DeFi Technologies Fails to Meet Nasdaq Listing Requirements for Review

The Smarter Web Acquires 35 Additional Bitcoins, Total Holdings Reach 2,747

The State Purchased 5,000 Pickup Trucks for the Armed Forces, Saving Over 2 Billion UAH

OKX founder announces 15-day reviews for deposits from high-risk addresses

IRGC Launches Missile and Drone Attacks on U.S. Military Bases

YAM Finance Faces Governance Takeover Attack, Attacker Submits Empty Proposal to Control Timelock

GoPro Merges with Starman Optical for $285 Million

Summary of Tool Call Results

95 BTC Transferred to Galaxy Digital Address

ECB Governing Council Member Mahrouf Calls for Readiness for Further Rate Hikes

Zelensky Criticizes Rada for Three Failed Bills Worth $4 Billion

Dunamu Receives the 56th Customs Commissioner Award

Joint Imaging Completes Hundreds of Millions in Financing

50% Chance of 50,000 Jobs Recovery in August

Alès: Couple Tied Up During Intrusion, Link to Cryptocurrencies Mentioned

SpaceX Restructures Data Center Leadership to Address Infrastructure Issues

U.S. Job Openings Rise to 7.27 Million in July, Labor Demand Remains Steady

BTC Spot Demand Turns Negative, Market Enters Phase of Spot Contraction and Futures Growth

Large Wallets Accumulate 60,000 BTC in August, Small Holders Reduce Holdings by 47,000 BTC

London Stock Exchange Launches Tokenized UK Stocks in Partnership with Payward

30-Year U.S. Treasury Yield Days Above 5% Reach Highest Level Since 2006














