• bitcoinBitcoin (BTC) $ 69,258.00
  • ethereumEthereum (ETH) $ 2,067.48
  • tetherTether (USDT) $ 0.999578
  • bnbBNB (BNB) $ 629.08
  • xrpXRP (XRP) $ 1.37
  • usd-coinUSDC (USDC) $ 0.999815
  • solanaSolana (SOL) $ 87.61
  • tronTRON (TRX) $ 0.311784
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • dogecoinDogecoin (DOGE) $ 0.091329
  • usdsUSDS (USDS) $ 0.999858
  • whitebitWhiteBIT Coin (WBT) $ 53.34
  • cardanoCardano (ADA) $ 0.257507
  • hyperliquidHyperliquid (HYPE) $ 39.05
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • bitcoin-cashBitcoin Cash (BCH) $ 462.13
  • leo-tokenLEO Token (LEO) $ 9.52
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 8.94
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 335.54
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • ethena-usdeEthena USDe (USDE) $ 0.998833
  • stellarStellar (XLM) $ 0.172814
  • canton-networkCanton (CC) $ 0.137451
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999347
  • daiDai (DAI) $ 0.999952
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 54.60
  • rainRain (RAIN) $ 0.008391
  • avalanche-2Avalanche (AVAX) $ 9.24
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • hedera-hashgraphHedera (HBAR) $ 0.090859
  • paypal-usdPayPal USD (PYUSD) $ 0.999913
  • memecoreMemeCore (M) $ 2.13
  • wethWETH (WETH) $ 2,268.37
  • zcashZcash (ZEC) $ 220.73
  • suiSui (SUI) $ 0.924627
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • usdt0USDT0 (USDT0) $ 0.998824
  • bittensorBittensor (TAO) $ 334.41
  • the-open-networkToncoin (TON) $ 1.29
  • crypto-com-chainCronos (CRO) $ 0.073266
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.097993
  • tether-goldTether Gold (XAUT) $ 4,423.76
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • mantleMantle (MNT) $ 0.703104
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • pax-goldPAX Gold (PAXG) $ 4,429.12
  • uniswapUniswap (UNI) $ 3.53
  • polkadotPolkadot (DOT) $ 1.31
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.187252
  • global-dollarGlobal Dollar (USDG) $ 0.999800
  • okbOKB (OKB) $ 84.21
  • falcon-financeFalcon USD (USDF) $ 0.998128
  • skySky (SKY) $ 0.071346
  • aster-2Aster (ASTER) $ 0.659952
  • aaveAave (AAVE) $ 106.65
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • nearNEAR Protocol (NEAR) $ 1.22
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ripple-usdRipple USD (RLUSD) $ 0.999751
  • pepePepe (PEPE) $ 0.000003
  • siren-2Siren (SIREN) $ 1.92
  • bitget-tokenBitget Token (BGB) $ 2.02
  • bfusdBFUSD (BFUSD) $ 0.998990
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • ethereum-classicEthereum Classic (ETC) $ 8.30
  • internet-computerInternet Computer (ICP) $ 2.30
  • ondo-financeOndo (ONDO) $ 0.255688
  • gatechain-tokenGate (GT) $ 6.60
  • quant-networkQuant (QNT) $ 75.13
  • kucoin-sharesKuCoin (KCS) $ 7.97
  • pump-funPump.fun (PUMP) $ 0.001775
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • kaspaKaspa (KAS) $ 0.036729
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.094350
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • worldcoin-wldWorldcoin (WLD) $ 0.304334
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • render-tokenRender (RENDER) $ 1.75
  • morphoMorpho (MORPHO) $ 1.64
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • nexoNEXO (NEXO) $ 0.892392
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.03
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • usdtbUSDtb (USDTB) $ 0.998360
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • cosmosCosmos Hub (ATOM) $ 1.71
  • ethenaEthena (ENA) $ 0.098318
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • aptosAptos (APT) $ 1.03
  • hash-2Provenance Blockchain (HASH) $ 0.014202
  • wbnbWrapped BNB (WBNB) $ 759.61
  • usddUSDD (USDD) $ 0.999697
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.084404
  • midnight-3Midnight (NIGHT) $ 0.045061
  • official-trumpOfficial Trump (TRUMP) $ 3.14
  • filecoinFilecoin (FIL) $ 0.886324
  • ousgOUSG (OUSG) $ 114.70
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007829
  • xdce-crowd-saleXDC Network (XDC) $ 0.031918
  • beldexBeldex (BDX) $ 0.083435
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.006800
  • yldsYLDS (YLDS) $ 0.999831
  • ghoGHO (GHO) $ 0.999169
  • arbitrumArbitrum (ARB) $ 0.094012
  • usual-usdUsual USD (USD0) $ 0.997552
  • stable-2​​Stable (STABLE) $ 0.025781
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.238499
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.150535
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • bonkBonk (BONK) $ 0.000006
  • layerzeroLayerZero (ZRO) $ 2.05
  • justJUST (JST) $ 0.058260
  • clbtcclBTC (CLBTC) $ 76,920.00
  • true-usdTrueUSD (TUSD) $ 0.998024
  • a7a5A7A5 (A7A5) $ 0.012057
  • fasttokenFasttoken (FTN) $ 1.09
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.40
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.689918
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006886
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • blockstackStacks (STX) $ 0.233076
  • euro-coinEURC (EURC) $ 1.15
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 32.74
  • ether-fiEther.fi (ETHFI) $ 0.521607
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • tezosTezos (XTZ) $ 0.372671
  • sei-networkSei (SEI) $ 0.058940
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999728
  • kite-2Kite (KITE) $ 0.217657
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • decredDecred (DCR) $ 21.90
  • riverRiver (RIVER) $ 19.16
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • hastra-primePRIME (PRIME) $ 1.03
  • usxUSX (USX) $ 0.999416
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • chilizChiliz (CHZ) $ 0.034706
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • dexeDeXe (DEXE) $ 7.40
  • cocaCOCA (COCA) $ 1.30
  • kinesis-goldKinesis Gold (KAU) $ 142.64
  • sun-tokenSun Token (SUN) $ 0.017287
  • curve-dao-tokenCurve DAO (CRV) $ 0.220956
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • apenftAINFT (NFT) $ 0.00000033
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • gnosisGnosis (GNO) $ 124.41
  • adi-tokenADI (ADI) $ 4.08
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • usdaiUSDai (USDAI) $ 0.999594
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • conflux-tokenConflux (CFX) $ 0.058957
  • aerodrome-financeAerodrome Finance (AERO) $ 0.326555
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 2.96
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kaiaKaia (KAIA) $ 0.048808
  • celestiaCelestia (TIA) $ 0.317584
  • venice-tokenVenice Token (VVV) $ 6.22
  • flokiFLOKI (FLOKI) $ 0.000029
  • bitcoin-svBitcoin SV (BSV) $ 13.88
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • fraxLegacy Frax Dollar (FRAX) $ 0.989939
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • spx6900SPX6900 (SPX) $ 0.285940
  • monadMonad (MON) $ 0.024481
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • official-foOfficial FO (FO) $ 0.264039
  • jasmycoinJasmyCoin (JASMY) $ 0.005315
  • the-graphThe Graph (GRT) $ 0.024396
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • crvusdcrvUSD (CRVUSD) $ 0.999044
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • kinesis-silverKinesis Silver (KAG) $ 67.50
  • syrupMaple Finance (SYRUP) $ 0.219738
  • doublezeroDoubleZero (2Z) $ 0.072657
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • iotaIOTA (IOTA) $ 0.057564
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • lido-daoLido DAO (LDO) $ 0.286860
  • olympusOlympus (OHM) $ 15.48
  • lighterLighter (LIT) $ 0.951296
  • thetrumptokenTheTrumpToken (GREAT) $ 12.14

Malicious packages empty dYdX user wallets

0 47

Malicious packages empty dYdX user wallets

Researchers have revealed that bad actors are targeting dYdX and using malicious packages to empty its user wallets. According to the report, some open source packages published on the npm and PyPi repositories were laced with code that stole wallet credentials from dYdX developers and backend systems.

dYdX is a decentralized derivatives exchange that supports hundreds of markets for perpetual trading. In the report, researchers from security firm Socket mentioned that all the applications using the compromised npm versions are at risk. They claimed the direct impact of the attacks has included complete wallet compromise and crypto thefts. The attack scope includes all the applications that depend on the compromised version, and both developer testing with real credentials and production end-users.

Malicious packages breach wallets associated with dYdX

According to the report, some of the packages that have been infected include npm (@dydxprotocol/v4-client-js):(3.4.1, 1.22.1, 1.15.2, 1.0.31 versions) and PyPI (dydx-v4-client): (1.1.5post1 version). Socket mentioned that the platform has processed more than $1.5 trillion in trading volume since it made its debut in the decentralized finance industry, with an average trading volume of $200 million to $540 million. In addition, the platform also has about $175 million in open interest.

The exchange provides code libraries that allow third-party applications for trading bots, automated strategies, or backend services, all of which involve mnemonics or private keys for signing. The npm malware embedded a malicious function in the legitimate package. When a seed phrase that underpins a wallet’s security is processed, the function copies it along with a fingerprint of the device running the application.

The fingerprint allows the threat actor to match stolen credentials to victims across several compromises. The domain receiving the seed phrases is dydx[.]priceoracle[.]site, which mimics the legitimate dYdX service at dydx[.]xyz through typosquatting. The malicious code available on PyPI continued the same credential theft function, although it implements a remote access Trojan (RAT) that allows execution of new malware on already infected systems.

The researchers noted that the backdoor received commands from dydx[.]priceoracle[.]site, adding that the domain was created and registered on January 9, 17 days before the malicious package was uploaded to PyPI. According to Socket, the RAT runs as a background daemon thread, beacons to the C2 server at a 10-second interval, receives Python code from the server, and executes it in an isolated subprocess with no visible output. In addition, it also uses a hard-coded authorization token.

New attack showcases disturbing trend

Socket added that once installed, the threat actors were able to carry out arbitrary Python code with user privileges, steal SSH keys, API credentials, and source code. In addition, they could also install persistent backdoors, exfiltrate sensitive files, monitor user activity, and modify critical files. The researchers added that the packages were published to npm and PyPI using official dYdX accounts, which meant they were compromised and used by the attackers.

While dYdX is yet to release a statement addressing the issue, this is at least the third time that it has been targeted in attacks. The previous incident occurred in September 2022 when a malicious code was uploaded to the npm repository. In 2024, the dYdX website was commandeered after the V3 website was hijacked through DNS. Users were redirected to a malicious website that prompted them to sign transactions designed to drain their wallets.

Socket claimed that this latest incident highlights a disturbing pattern of adversaries targeting dYdX-related assets using trusted distribution channels. It noted that the attackers knowingly compromised packages in the npm and PyPI ecosystems to expand the attack surface to reach JavaScript and Python developers working with the platform. Anyone using the platform should carefully examine all applications for dependencies on the malicious packages.

Source

Leave A Reply

Your email address will not be published.