Skip to content
SlowMist Discovers Cross-Registry Supply Chain Attack Targeting Developers

SlowMist Discovers Cross-Registry Supply Chain Attack Targeting Developers

Kucoin May 25, 2026

According to SlowMist monitoring, MistEye detected that attackers have published over 34 malicious packages and over 384 related versions via npm, PyPI, and Crates.io, targeting developers in crypto, DeFi, Solana, Sui/Move, and AI. The attacks involve stealing cryptocurrency wallets, SSH keys, cloud credentials, and other data, while attempting to achieve persistence through multiple methods. SlowMist recommends removing affected packages, isolating systems, rotating credentials, and rebuilding development environments from clean images.

Extracted Entities

Attack Types (1)

Tools (1)