Back Kucoin SlowMist Discovers Cross-Registry Supply Chain Attack Targeting Developers
According to SlowMist monitoring, MistEye detected that attackers have published over 34 malicious packages and over 384 related versions via npm, PyPI, and Crates.io, targeting developers in crypto, DeFi, Solana, Sui/Move, and AI. The attacks involve stealing cryptocurrency wallets, SSH keys, cloud credentials, and other data, while attempting to achieve persistence through multiple methods. SlowMist recommends removing affected packages, isolating systems, rotating credentials, and rebuilding development environments from clean images.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
