Skip to content
Supply chain attack targets crypto and AI developers via npm/PyPI/crates.io

Supply chain attack targets crypto and AI developers via npm/PyPI/crates.io

Kucoin May 25, 2026

Huo Xing Cai Jing reports that, according to SlowMist, the security firm MistEye detected a supply chain attack targeting registries. Attackers distributed malicious packages to npm, PyPI, and crates.io, targeting developers in the cryptocurrency, DeFi, Solana, Sui/Move, and AI sectors. The attack involved over 34 malicious packages and more than 384 associated versions. The attackers may have stolen cryptocurrency wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and other developer secrets. Some malicious payloads also attempted to achieve persistent persistence via .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH. Developers are advised to immediately remove affected packages, isolate compromised systems, retain logs, rotate exposed credentials, rebuild CI environments and developer machines from clean images, and review activity logs for GitHub, cloud services, SSH, and wallet access.

Extracted Entities