MistEye Detects 34+ Malicious Packages in Cross-Registry Supply Chain Attack Targeting Crypto, DeFi, and AI Developers on May 25

SOL-0.32%
SUI-0.52%
MOVE0.8%
According to Slow Mist, on May 25, security firm MistEye detected a cross-registry supply chain attack targeting cryptocurrency, DeFi, Solana, Sui/Move, and AI developers. Attackers deployed over 34 malicious packages and 384+ related versions across npm, PyPI, and crates.io. The malicious payloads can steal cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and developer secrets. Some payloads also attempt to establish persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments