Malicious npm/PyPI packages used to drain dYdX wallets via compromised dYdX libraries

Security researchers at Socket reported that attackers published malicious versions of official dYdX client libraries to npm and PyPI, stealing wallet seed phrases and device fingerprints to drain user wallets. Affected packages include npm @dydxprotocol/v4-client-js (versions 3.4.1, 1.22.1, 1.15.2, 1.0.31) and PyPI dydx-v4-client (1.1.5post1). The npm payload exfiltrated seed phrases and a device fingerprint to a typosquatted domain (dydx[.]priceoracle[.]site), while the PyPI package added a RAT that beacons to the same command-and-control server, can run arbitrary Python code, steal SSH keys and API credentials, and persist on systems. Socket says the malicious packages were published using compromised official dYdX accounts and warned that all applications depending on these versions — including developer testing with real credentials and production services — are at risk. dYdX has not yet issued a public response. Researchers note this is at least the third targeting of dYdX via supply-chain or DNS attacks (notable incidents in Sept 2022 and a 2024 DNS hijack), highlighting a growing trend of attackers abusing trusted distribution channels. Traders and dev teams are advised to audit dependencies, rotate keys/mnemonics, and inspect systems for backdoors or exfiltration indicators.
Bearish
This incident is bearish for crypto market sentiment, especially for assets tied to decentralized exchanges and developer ecosystems. Supply-chain compromises that directly drain user wallets increase perceived operational and custodial risk, likely reducing trader confidence and encouraging short-term selling or risk-off behavior. Similar past supply-chain or UI-hijack attacks (e.g., previous dYdX npm incident in Sept 2022 and DNS hijack in 2024) caused immediate user losses and temporary outflows. Short-term effects: increased withdrawals from dYdX and other DeFi venues, higher volatility, and sell pressure on related tokens. Medium-to-long term: projects may face higher costs for security audits, tighter access controls, and slower developer adoption, which can dampen growth expectations until supply-chain measures improve. However, if exchanges and projects respond quickly with transparent mitigation, key rotations, and incident disclosures, confidence may recover. For traders: monitor on-chain flows, dYdX liquidity metrics, and announcements; avoid interacting with affected clients and consider reducing exposure to protocols showing repeated operational weaknesses.