Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Flush With Cash From OpenAI, Opal Is Making an AI-Powered Audio Gadget
    • Dozens of Red Hat packages backdoored through its official NPM channel
    • Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools
    • From Regex to Vision Models: Which RAG Technique Fits Which Problem
    • Rehumanizing global health care with agentic AI
    • Robots-Blog | Praxisprojekt mit fischertechnik an der Hochschule Hof in Bayern
    • Ancient giant octopuses were apex predators, study finds
    • Barcelona’s Zazume raises €2.5 million to scale its AI-powered rental management platform
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Tuesday, June 2
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Malicious packages for dYdX cryptocurrency exchange empties user wallets
    News

    Malicious packages for dYdX cryptocurrency exchange empties user wallets

    Editor Times FeaturedBy Editor Times FeaturedFebruary 8, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Open supply packages printed on the npm and PyPI repositories had been laced with code that stole pockets credentials from dYdX builders and backend programs and, in some circumstances, backdoored gadgets, researchers mentioned.

    “Each utility utilizing the compromised npm variations is in danger ….” the researchers, from safety agency Socket, said Friday. “Direct influence consists of full pockets compromise and irreversible cryptocurrency theft. The assault scope consists of all functions relying on the compromised variations and each builders testing with actual credentials and manufacturing end-users.”

    Packages that had been contaminated had been:

    npm (@dydxprotocol/v4-client-js):

    • 3.4.1
    • 1.22.1
    • 1.15.2
    • 1.0.31

    PyPI (dydx-v4-client):

    Perpetual buying and selling, perpetual concentrating on

    dYdX is a decentralized derivatives change that helps a whole lot of markets for “perpetual buying and selling,” or the usage of cryptocurrency to wager that the worth of a spinoff future will rise or fall. Socket mentioned dYdX has processed over $1.5 trillion in buying and selling quantity over its lifetime, with a mean buying and selling quantity of $200 million to $540 million and roughly $175 million in open curiosity. The change supplies code libraries that enable third-party apps for buying and selling bots, automated methods, or backend companies, all of which deal with mnemonics or non-public keys for signing.

    The npm malware embedded a malicious operate within the official bundle. When a seed phrase that underpins pockets safety was processed, the operate exfiltrated it, together with a fingerprint of the machine working the app. The fingerprint allowed the risk actor to correlate stolen credentials to trace victims throughout a number of compromises. The area receiving the seed was dydx[.]priceoracle[.]web site, which mimics the official dYdX service at dydx[.]xyz by typosquatting.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    CFTC seeks injunction in Kalshi Rhode Island dispute

    June 2, 2026

    Florida crackdown targets illegal machines in Sarasota

    June 2, 2026

    Hawthorne bankruptcy dispute targets Illinois racing funds

    June 2, 2026

    Kalshi debuts regulated crypto perpetual futures

    June 2, 2026

    Manchester gambling raid sparks wider enforcement focus

    June 2, 2026

    Comments are closed.

    Editors Picks

    Flush With Cash From OpenAI, Opal Is Making an AI-Powered Audio Gadget

    June 2, 2026

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    Microsoft Build 2026 Kicks Off Today: Live Updates on Copilot AI and Dev Tools

    June 2, 2026

    From Regex to Vision Models: Which RAG Technique Fits Which Problem

    June 2, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Berlin-based Mirelo raises €35 million seed round co-led by Index Ventures and Andreessen Horowitz

    December 15, 2025

    Today’s NYT Mini Crossword Answers for April 19

    April 19, 2025

    AI’s Copyright Dilemma Affects All of Us, Even You. Here’s What You Need to Know

    November 10, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.