Supply chain attacks affect PyPI/npm/crates.io, with over 34 malicious packages targeting cryptocurrency and AI developers
According to Slow Fog's disclosure, the security agency MistEye detected a cross-registry supply chain attack incident, where attackers targeted developers in the fields of cryptocurrency, DeFi, Solana, Sui/Move, and AI by publishing malicious packages on npm, PyPI, and crates.io. This attack activity includes more than 34 malicious packages and over 384 related versions. The attackers may steal cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and developers' confidential information.
Some of the malicious payloads also attempted to achieve persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH. Developers are advised to immediately remove the affected packages, isolate the affected systems, retain logs, rotate exposed credentials, rebuild CI environments and developer machines from clean images, and review GitHub, cloud services, SSH, and wallet activity logs.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Mexican Pleads Guilty to Laundering 4 Million Dollars Through Cryptocurrencies

Significant Decline in Economic Confidence Among American Republicans

Local Ceasefire for Repairing Power Line at Zaporizhzhia Nuclear Power Plant

Account Purchases $74,600 Bet on Fed Keeping Rates Steady in September

Southeast Asian Blockchain Companies Raise $680 Million in Funding This Year, Rounds Decrease to 25

Robinhood CEO Believes Tokenization Will Enhance Access to Global Financial Assets

Router Protocol to Cease Operations on September 30, 2026

South Korean Man Sentenced to One Year in Prison for Failing to Declare Cryptocurrency Withdrawal Operations

Importing Phones Requires IMEI Code Registration from September 4

Probability of CPI Exceeding 3% in 2026 at 100%, Interest Rate Hike Probability at 52%

Ukrzaliznytsia Plans to Increase Grain Transit Through Moldova to 4.5 Million Tons Per Year

BitcoinHabebe Focuses on $TOWNS Trend

University of Florida Signs Sponsorship Agreement with Ripple Worth $5 Million Annually

U.S. Treasury Yields Steady as Market Awaits August Nonfarm Payroll Data

SEC Proposes to Repeal Political Contribution Regulations

Ferrexpo Raises $100 Million, Veresky Invests $50 Million

JPMorgan Maintains Nvidia Overweight Rating, Target Price $320

唐华斑竹: Hyperliquid's Top Five 24-Hour Trading Volumes are All Crypto Assets

Norwegian Sovereign Wealth Fund Plans to Cut US Treasury Holdings by $80 Billion

Vance: No Dialogue with Iran Until Attacks on Merchant Ships Cease

Kyiv City Council Approves Capitalization of 'Kyivgorstroy' for 3 Billion UAH

CNV Eases Rules for Credit Rating Agencies

European Commission Calls for Agreement on Funding Patriot Missiles for Ukraine

Apple Faces $2.7 Billion Class Action Lawsuit Over Unfair App Tracking Rules

Humain Plans to Raise $2.5 Billion to Establish Data Center Investment Fund

Pencil Finance Completes $1 Million On-Chain Student Loan Cycle, Benefiting 6,600 Students

predict.fun Predicts 85% Chance of BLG Defeating WE

Europe Imports 90,000 Tons of Diesel from South Korea

NBU Authorizes 14 Non-Bank Institutions for Acquiring Services














