The post dYdX targeted as malicious packages empty its user wallets appeared on BitcoinEthereumNews.com. Researchers have revealed that bad actors are targetingThe post dYdX targeted as malicious packages empty its user wallets appeared on BitcoinEthereumNews.com. Researchers have revealed that bad actors are targeting

dYdX targeted as malicious packages empty its user wallets

2026/02/07 18:22
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

Researchers have revealed that bad actors are targeting dYdX and using malicious packages to empty its user wallets. According to the report, some open source packages published on the npm and PyPi repositories were laced with code that stole wallet credentials from dYdX developers and backend systems.

dYdX is a decentralized derivatives exchange that supports hundreds of markets for perpetual trading. In the report, researchers from security firm Socket mentioned that all the applications using the compromised npm versions are at risk. They claimed the direct impact of the attacks has included complete wallet compromise and crypto thefts. The attack scope includes all the applications that depend on the compromised version, and both developer testing with real credentials and production end-users.

Malicious packages breach wallets associated with dYdX

According to the report, some of the packages that have been infected include npm (@dydxprotocol/v4-client-js):(3.4.1, 1.22.1, 1.15.2, 1.0.31 versions) and PyPI (dydx-v4-client): (1.1.5post1 version). Socket mentioned that the platform has processed more than $1.5 trillion in trading volume since it made its debut in the decentralized finance industry, with an average trading volume of $200 million to $540 million. In addition, the platform also has about $175 million in open interest.

The exchange provides code libraries that allow third-party applications for trading bots, automated strategies, or backend services, all of which involve mnemonics or private keys for signing. The npm malware embedded a malicious function in the legitimate package. When a seed phrase that underpins a wallet’s security is processed, the function copies it along with a fingerprint of the device running the application.

The fingerprint allows the threat actor to match stolen credentials to victims across several compromises. The domain receiving the seed phrases is dydx[.]priceoracle[.]site, which mimics the legitimate dYdX service at dydx[.]xyz through typosquatting. The malicious code available on PyPI continued the same credential theft function, although it implements a remote access Trojan (RAT) that allows execution of new malware on already infected systems.

The researchers noted that the backdoor received commands from dydx[.]priceoracle[.]site, adding that the domain was created and registered on January 9, 17 days before the malicious package was uploaded to PyPI. According to Socket, the RAT runs as a background daemon thread, beacons to the C2 server at a 10-second interval, receives Python code from the server, and executes it in an isolated subprocess with no visible output. In addition, it also uses a hard-coded authorization token.

New attack showcases disturbing trend

Socket added that once installed, the threat actors were able to carry out arbitrary Python code with user privileges, steal SSH keys, API credentials, and source code. In addition, they could also install persistent backdoors, exfiltrate sensitive files, monitor user activity, and modify critical files. The researchers added that the packages were published to npm and PyPI using official dYdX accounts, which meant they were compromised and used by the attackers.

While dYdX is yet to release a statement addressing the issue, this is at least the third time that it has been targeted in attacks. The previous incident occurred in September 2022 when a malicious code was uploaded to the npm repository. In 2024, the dYdX website was commandeered after the V3 website was hijacked through DNS. Users were redirected to a malicious website that prompted them to sign transactions designed to drain their wallets.

Socket claimed that this latest incident highlights a disturbing pattern of adversaries targeting dYdX-related assets using trusted distribution channels. It noted that the attackers knowingly compromised packages in the npm and PyPI ecosystems to expand the attack surface to reach JavaScript and Python developers working with the platform. Anyone using the platform should carefully examine all applications for dependencies on the malicious packages.

Source: https://www.cryptopolitan.com/dydx-malicious-packages-empty-user-wallets/

Opportunità di mercato
Logo dYdX
Valore dYdX (DYDX)
$0.09916
$0.09916$0.09916
+3.13%
USD
Grafico dei prezzi in tempo reale di dYdX (DYDX)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

This article explores how a simple change in the reference point can achieve a Pareto-efficient equilibrium in both free and fair economies and those with social justice.
Condividi
Hackernoon2025/09/17 22:30
Justin Baldoni Taps SBF’s Lawyer Amid Blake Lively Legal Saga

Justin Baldoni Taps SBF’s Lawyer Amid Blake Lively Legal Saga

Justin Baldoni has tapped disgraced FTX founder Sam Bankman-Fried’s (SBF) lawyer to represent him as his legal fight against Blake Lively intensifies, court documents obtained by People on Thursday reveal. Alexandra Shapiro Set To Rep Baldoni In Landmark Lively Case The “It Ends With Us” director has brought in Alexandra Shapiro to represent him ahead of his March 2026 trial against his former co-star, per a notice of appearance filed by Shapiro and verified by People. A former clerk for Supreme Court Justice Ruth Bader Ginsburg, Shapiro is currently representing Bankman-Fried as he appeals his November 2023 conviction on seven fraud and conspiracy charges tied to FTX’s stunning collapse back in 2022. Rapper Sean “Diddy” Combs – who previously was a cellmate of Bankman-Fried in New York federal prison – also hired Shapiro in the lead-up to his July 2025 partial acquittal on racketeering and sex trafficking charges. Taylor Swift Shakes Off Justin Baldoni Deposition News of Baldoni’s latest legal move comes just one week after Judge Lewis Liman rejected his team’s request for an extension to depose Taylor Swift – a longtime friend of Lively’s, though their current relationship status remains unclear. Liman argued that Baldoni’s lawyers waited too long to depose Swift and noted that Baldoni’s camp had withdrawn a subpoena sent to the pop star this past spring after voluntarily being provided information by Swift’s legal team. “Discovery has been going on in this case for approximately six months,” Liman said. “They have offered no evidence that they have served a renewed subpoena on Swift… Having failed to demonstrate appropriate diligence, the requested extension is denied.” SBF Awaits Key Appeal Date Meanwhile, Bankman-Fried is serving his 25-year sentence for orchestrating the massive crypto scheme behind bars at FCI Terminal Island, a low-security prison in his home state of Southern California. Oral arguments for his appeal are scheduled for November 4 at the U.S. Court of Appeals for the Second Circuit in New York. However, with the average criminal appeal success rate historically low, it remains to be seen if Shapiro will be successful in overturning Bankman-Fried’s conviction
Condividi
CryptoNews2025/09/20 13:58
XLM Price Prediction: Stellar Targets $0.20 by Mid-2026 Amid Technical Consolidation

XLM Price Prediction: Stellar Targets $0.20 by Mid-2026 Amid Technical Consolidation

Stellar (XLM) trades at $0.17 with neutral RSI at 51.27. Technical analysis suggests potential upside to $0.20 mid-2026 target, with key resistance at $0.18 and
Condividi
BlockChain News2026/03/31 15:54