Security researchers reported a supply-chain compromise affecting official dYdX v4 client libraries distributed via npm and PyPI, where attackers published poisoned versions designed to steal cryptocurrency wallet secrets and enable follow-on compromise. The impacted packages were identified as @dydxprotocol/v4-client-js on npm (malicious versions 3.4.1, 1.22.1, 1.15.2, 1.0.31) and dydx-v4-client on PyPI (including 1.1.5post1), which are commonly used by trading bots, automated strategies, and backend services that handle sensitive material such as seed phrases/private keys for signing.
Analysis attributed the distribution method to likely developer account/publishing credential compromise, since the rogue releases were pushed using legitimate publishing credentials. The npm payload embedded logic to exfiltrate wallet seed phrases and a device fingerprint to a typosquatted domain, dydx[.]priceoracle[.]site, enabling correlation of victims across compromises and potentially irreversible cryptocurrency theft; reporting also noted that some infections could backdoor developer devices. The PyPI package was assessed as more severe, combining wallet-stealing with a remote access trojan (RAT) that executes on import and beacons to dydx[.]priceoracle[.]site/py to fetch and run attacker commands (including Windows execution behavior intended to reduce user visibility).

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
In related analysis, Aikido highlighted the risk of attackers later claiming package names referenced in documentation but never actually published to npm. The firm recommended mitigations including using npx --no-install and explicitly installing CLI tools.
Security researchers at Socket and Aikido publicly reported that the compromised dYdX packages exfiltrated seed phrases, private keys, and device fingerprints, with stolen data sent to a typosquatted domain resembling dYdX. They warned that both developers and production users could be affected, including through wallet theft and, in some cases, device backdooring.
After receiving responsible disclosure on January 28, 2026, dYdX acknowledged the incident and confirmed that affected npm and PyPI packages had been compromised, while GitHub-hosted versions were not malicious. The company advised users to isolate affected machines, move funds to a new wallet from a clean system, and rotate API keys and other credentials.
Attackers compromised legitimate dYdX-related package publishing accounts and republished malicious versions of @dydxprotocol/v4-client-js on npm and dydx-v4-client on PyPI. The npm payload stole wallet seed phrases and device information, while the PyPI package added remote-access functionality that executed on import and fetched commands from an external server.
The dYdX ecosystem had previously been targeted in 2022 when an npm account hijack led to a compromise of a dYdX-related package. Researchers later cited this as part of a recurring pattern of attacks against dYdX software distribution channels.
At a later, unspecified date after the 2022 npm incident, a dYdX v3-related website was compromised and used to redirect users to phishing pages designed to drain cryptocurrency wallets. This was referenced as another prior attack in the same ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.