logo

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

ID: d8117231-541c-5b0f-bcb5-dffb6b0ed8e3

STIX ID: report--d8117231-541c-5b0f-bcb5-dffb6b0ed8e3

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers discovered that dYdX client packages on npm and PyPI were compromised to deliver malicious versions that steal cryptocurrency wallet seed phrases and device data; the PyPI package additionally installs a RAT that fetches commands from an external server. The actor likely had developer publishing access, enabling coordinated cross-ecosystem deployment, and maintainers and users were urged to isolate affected systems, move funds from clean environments, and rotate credentials; the report also highlights risks from unclaimed/phantom npm package names and provides mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.