Hackers target dYdX cryptocurrency exchange by lacing open-source packages with malicious code, emptying user wallets.
A security firm has warned that hackers have compromised open-source packages published on the npm and PyPI repositories, using them to steal wallet credentials from dYdX developers and backend systems. The malicious code embedded in the packages exfiltrated seed phrases, which are used to secure wallets, along with device fingerprints, allowing the attackers to track victims across multiple compromises.
The compromised packages include:
* npm version @dydxprotocol/v4-client-js version 3.4.1
* npm version @dydxprotocol/v4-client-js version 1.22.1
* PyPI package dydx-v4-client version 1.1.5post1
The malicious code also implemented a remote access Trojan (RAT) that allowed the execution of new malware on infected systems, receiving commands from a domain registered 17 days before the malicious package was uploaded to PyPI.
The incident is at least the third time dYdX has been targeted in attacks. The security firm warns that any user using the platform should carefully examine all apps for dependencies on the malicious packages listed above.
A security firm has warned that hackers have compromised open-source packages published on the npm and PyPI repositories, using them to steal wallet credentials from dYdX developers and backend systems. The malicious code embedded in the packages exfiltrated seed phrases, which are used to secure wallets, along with device fingerprints, allowing the attackers to track victims across multiple compromises.
The compromised packages include:
* npm version @dydxprotocol/v4-client-js version 3.4.1
* npm version @dydxprotocol/v4-client-js version 1.22.1
* PyPI package dydx-v4-client version 1.1.5post1
The malicious code also implemented a remote access Trojan (RAT) that allowed the execution of new malware on infected systems, receiving commands from a domain registered 17 days before the malicious package was uploaded to PyPI.
The incident is at least the third time dYdX has been targeted in attacks. The security firm warns that any user using the platform should carefully examine all apps for dependencies on the malicious packages listed above.