logo

Crypto malware attacks: 23 supply chain incidents set off alarms

ID: e2d2f71d-80ac-5eaf-8d4d-643864ea916a

STIX ID: report--e2d2f71d-80ac-5eaf-8d4d-643864ea916a

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2025-03-25

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

ReversingLabs' 2025 Software Supply Chain Security Report documents 23 cryptocurrency-focused supply-chain attacks in 2024 targeting npm and PyPI, ranging from typosquatting campaigns (e.g., BIPClip) to more sophisticated compromises—such as a malicious update to a previously legitimate Python crypto client (aiocpa) and injected exfiltration code in popular @solana/web3.js releases—demonstrating growing attacker sophistication and financial motivation and underscoring the need for stronger OSS supply-chain security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.