Supply chain attacks affect PyPI/npm/crates.io, with over 34 malicious packages targeting cryptocurrency and AI developers
According to Slow Fog's disclosure, the security agency MistEye detected a cross-registry supply chain attack incident, where attackers targeted developers in the fields of cryptocurrency, DeFi, Solana, Sui/Move, and AI by publishing malicious packages on npm, PyPI, and crates.io. This attack activity includes more than 34 malicious packages and over 384 related versions. The attackers may steal cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and developers' confidential information.
Some of the malicious payloads also attempted to achieve persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH. Developers are advised to immediately remove the affected packages, isolate the affected systems, retain logs, rotate exposed credentials, rebuild CI environments and developer machines from clean images, and review GitHub, cloud services, SSH, and wallet activity logs.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

European Commission Approves €6.1 Billion for Ukraine's Drones and Patriot Missiles

ether.fi Loses Approximately 15.45 ETH Due to AtomicQueue Contract Vulnerability

EU Resumes Work on Transferring Frozen Russian Assets to Ukraine

Unauthorized Access to Japan's Digital Agency Server, Personal Information of 246,000 Individuals May Have Been Leaked

MKB Identifies Problematic Loans Worth $8 Billion

Oil Production in Russia Falls to 8.718 Million Barrels per Day

JPMorgan: US Treasury Buyback Data Indicates Decline in Bid Quality

Choi Won-seok, CEO of Finiverse, Proposes Use of Won Stablecoin for SME Trade Settlements

Iran and Gulf States Foreign Ministers' Meeting Promotes Hormuz Strait Agreement

Murata to Cease Production of Certain MLCCs, Potential Orders Shift to Yageo, Walsin, and Others

Codex Suspends New $200 Pro Plan Subscriptions to Ensure Astra User Experience

Ministry of Industry and Information Technology Issues Implementation Plan for 'Artificial Intelligence + Software' Special Action

Loans up to 1 billion UAH, state property rental, and business security

Estonia to Impose Sanctions on Transit of Russian Grain

Ripple Expands AI Feature GSmart in Ripple Treasury

Inflation Report Key to Fed Rate Hike

Xiaomi Open Sources Xiaomi-Robotics-U0 Embodied World Model

New Underground Money Laundering Scheme Using Virtual Currency, Seven Sentenced

Ant Group Partners with Visa and Mastercard to Establish AI Agent Payment Standards

U.S. Treasury Secretary Removes CIO Sam Corcos from AI Policy Work

EU Includes Crypto Service Providers in Local Contact Person Mechanism

Economy Seeks to Renew 8.13 Trillion Pesos in Debt Before 2027 Elections

Texas Data Center Development Halted, US Power Sales Growth Forecast Downgraded

Typical Family in CABA Needs 2,603,556 Pesos to Be Considered Middle Class

Hyperliquid Policy Center Requests Dismissal of CME's Lawsuit Against CFTC

US Central Command Denies Naval Vessels Were Attacked

Osmosis Freezes 22.65 BTC from Nomic Chain Attacker's Address

Flop Labs Launches KOL Ranking Program

Bebop Launches Multi-Maker Proprietary AMM Infrastructure bopAMM











