Crypto malware attacks: 23 supply chain incidents set off alarms
ID: e2d2f71d-80ac-5eaf-8d4d-643864ea916a
STIX ID: report--e2d2f71d-80ac-5eaf-8d4d-643864ea916a
Feed Name: ReversingLabs Blog
Date Published: 2025-03-25
Date Updated: 2026-04-29
Author: [email protected] (Carolynn van Arsdale)
ReversingLabs' 2025 Software Supply Chain Security Report documents 23 cryptocurrency-focused supply-chain attacks in 2024 targeting npm and PyPI, ranging from typosquatting campaigns (e.g., BIPClip) to more sophisticated compromises—such as a malicious update to a previously legitimate Python crypto client (aiocpa) and injected exfiltration code in popular @solana/web3.js releases—demonstrating growing attacker sophistication and financial motivation and underscoring the need for stronger OSS supply-chain security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
