Supply chain attacks affect PyPI/npm/crates.io, with over 34 malicious packages targeting cryptocurrency and AI developers
According to Slow Fog's disclosure, the security agency MistEye detected a cross-registry supply chain attack incident, where attackers targeted developers in the fields of cryptocurrency, DeFi, Solana, Sui/Move, and AI by publishing malicious packages on npm, PyPI, and crates.io. This attack activity includes more than 34 malicious packages and over 384 related versions. The attackers may steal cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and developers' confidential information.
Some of the malicious payloads also attempted to achieve persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH. Developers are advised to immediately remove the affected packages, isolate the affected systems, retain logs, rotate exposed credentials, rebuild CI environments and developer machines from clean images, and review GitHub, cloud services, SSH, and wallet activity logs.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Scott Bessent Blames Ukraine for Global Energy Crisis

Anthropic Upgrades Claude Code/Cowork to Control User Macs in the Background

Ledger Faces Class Action Lawsuit in New York for Incomplete Disclosure of Security Incident

CFTC Requests Dismissal of CME's Motion on Perpetual Contracts Lawsuit

U.S. Stock Market Fear Index Plummets to 31.3, Concerns Over September Effect

New Jersey Seeks Supreme Court Review of Kalshi Sports Betting Contracts Case

Wonderful Completes $550 Million Series C Financing, Valuation Reaches $5 Billion

Ribas Hotels Group Invests 150 Million UAH in Hotel on Karolino-Buhaz Spit

Hungary to Introduce Wealth Tax, Expected Revenue of $1.86 Billion

Securitize Partners with Socios to Launch Sports Equity Tokenization Program

Tether Releases Open Source AI Translation Models Supporting African and European Languages

Argentine President Milei's Social Media Influence Drops by 72%

State Geological Service Files Six Lawsuits to Terminate Subsoil Use Permits

DeFi Technologies Fails to Meet Nasdaq Listing Requirements for Review

The Smarter Web Acquires 35 Additional Bitcoins, Total Holdings Reach 2,747

The State Purchased 5,000 Pickup Trucks for the Armed Forces, Saving Over 2 Billion UAH

OKX founder announces 15-day reviews for deposits from high-risk addresses

IRGC Launches Missile and Drone Attacks on U.S. Military Bases

YAM Finance Faces Governance Takeover Attack, Attacker Submits Empty Proposal to Control Timelock

GoPro Merges with Starman Optical for $285 Million

Summary of Tool Call Results

95 BTC Transferred to Galaxy Digital Address

ECB Governing Council Member Mahrouf Calls for Readiness for Further Rate Hikes

Zelensky Criticizes Rada for Three Failed Bills Worth $4 Billion

Dunamu Receives the 56th Customs Commissioner Award

Joint Imaging Completes Hundreds of Millions in Financing

50% Chance of 50,000 Jobs Recovery in August

Alès: Couple Tied Up During Intrusion, Link to Cryptocurrencies Mentioned

SpaceX Restructures Data Center Leadership to Address Infrastructure Issues















