BitcoinThe Massive Supply Chain Attack Targeting Crypto Developers

The Massive Supply Chain Attack Targeting Crypto Developers

-


Key Takeaways

Supply Chain Attack Scheme Trapdoor Targets Developers For Maximum Performance

While some malware campaigns target everyday crypto users, others focus on developers, aiming to capture targets with a higher chance of holding large amounts of cryptocurrency and having access to broader resources.

Researchers at Socket, a company that specializes in preventing supply chain attacks, have identified a broad campaign targeting crypto developers using infected packages across npm, PyPI, and Crates.io.

Trapdoor Malware: The Massive Supply Chain Attack Targeting Crypto Developers

Dubbed Trapdoor, the supply chain attack spans 34 packages across these development environments, encompassing over 384 versions, with some still available. Socket reported that the affected packages were published in waves starting on May 22 and then were updated throughout the following weekend.

The packages stood out due to their nature, as they allegedly represented generic developer tools and appeared in quick succession across different registries. This gives the campaign “broad reach across adjacent developer communities where crypto wallets, cloud credentials, Github tokens, and SSH keys are likely to be present,” socket assessed.

The infected packages invade the development environment of crypto developers, leveraging these alleged open-source tools, taking hold of secrets, crypto wallets, secure shell (SSH) keys, and other relevant data.

Trapdoor infected packages also try to leverage AI tools to collaborate with their attack, using directive files to trick AI coding tools to run a security scan and exfiltrate highly sensitive data.

Socket stated that while this technique could not work consistently across all AI tools and models, its presence shows that attackers “are actively experimenting with AI development environments as part of supply chain malware campaigns.”

Chain attacks are becoming more common. In September, the crypto community was alerted about a similar hack, with several packages used by crypto wallets being compromised and modified to steal cryptocurrency funds from wallets containing bitcoin, ether, and solana, among other digital assets.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

ETH Battles 100-Day MA as $2K Support Holds the Key

Ethereum is trading at $2,120 as the final week of May begins, caught in a tug-of-war with the...

Memorial Day Tech Deals: Sony, Apple, Anker, and More

When you think of Memorial Day sales, you probably think of mattresses and other home goods. And while...

SEC Issues Cease and Desist: Orders BG Wealth to Stop Crypto Investment Operations in PH

The Philippine Securities and Exchange Commission (SEC) has issued a cease and desist order against BG Wealth Sharing...

Paul Graham says Warren crypto stance was own goal

Paul Graham, co-founder of Y Combinator,...

Advertisement

Startup Battlefield 200 applications close before May 27  | TechCrunch

The deadline to apply or nominate for Startup Battlefield 200 is Friday, May 27. This program is your shot at VC access, global visibility,...

CZ Denies Viral Rumors of Surfing Accident in Dubai

CZ noted that a safety boat always follows him when he kitesurfs, making the scenario of being dragged...

Must read

ETH Battles 100-Day MA as $2K Support Holds the Key

Ethereum is trading at $2,120 as the final...

Memorial Day Tech Deals: Sony, Apple, Anker, and More

When you think of Memorial Day sales, you...

You might also likeRELATED
Recommended to you