<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3" -->

---
title: Malicious dYdX Packages Published to npm and PyPI After...
description: Socket&#x27;s Threat Research Team discovered a supply chain attack on dYdX protocol packages across npm and PyPI. Malicious versions of @dydxprotocol/v4-client-js...
canonical: https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious dYdX Packages Published to npm and PyPI After Main... | daily.dev
og:description: Socket&#x27;s Threat Research Team discovered a supply chain attack on dYdX protocol packages across npm and PyPI. Malicious versions of @dydxprotocol/v4-client-js...
og:url: https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3
og:image: https://api.daily.dev/og/posts/bwRxiW1f3.png
og:image:alt: Malicious dYdX Packages Published to npm and PyPI After Main...
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious dYdX Packages Published to npm and PyPI After Main...

**[Socket](https://daily.dev/sources/socketdev)** · 10 min read · 0 upvotes · 0 comments

## Summary

Socket's Threat Research Team discovered a supply chain attack on dYdX protocol packages across npm and PyPI. Malicious versions of @dydxprotocol/v4-client-js and dydx-v4-client were published after maintainer compromise, containing credential theft malware that exfiltrates cryptocurrency wallet seed phrases and device fingerprints. The PyPI version additionally included a Remote Access Trojan enabling arbitrary code execution. The attack targeted developers building trading bots and DeFi applications, with the malicious infrastructure registered weeks before the compromise. This follows previous attacks on dYdX infrastructure in 2022 and 2024, demonstrating persistent targeting of cryptocurrency development tools.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/malicious-dydx-packages-published-to-npm-and-pypi>

## Similar posts on daily.dev

- [Four More Supply Chain Attacks Hit npm and PyPI](https://daily.dev/posts/four-more-supply-chain-attacks-hit-npm-and-pypi-g68buqqbp) · GitGuardian · 7 upvotes · 0 comments
- [New npm supply-chain attack self-spreads to steal auth tokens](https://daily.dev/posts/new-npm-supply-chain-attack-self-spreads-to-steal-auth-tokens-p3mykawe4) · BleepingComputer · 122 upvotes · 17 comments

---

Tags: [#security](https://daily.dev/tags/security), [#python](https://daily.dev/tags/python), [#crypto](https://daily.dev/tags/crypto), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious dYdX Packages Published to npm and PyPI After Main...","url":"https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3"},"datePublished":"2026-02-06T01:28:07.840Z","dateModified":"2026-02-26T21:09:27.060Z","description":"Socket's Threat Research Team discovered a supply chain attack on dYdX protocol packages across npm and PyPI. Malicious versions of @dydxprotocol/v4-client-js...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb517ef283bb5b1c545654d9a6b6198a?_a=AQAEunF","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb517ef283bb5b1c545654d9a6b6198a?_a=AQAEunF","isAccessibleForFree":true,"articleSection":"Socket","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Socket","logo":"https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev","url":"https://daily.dev/sources/socketdev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/malicious-dydx-packages-published-to-npm-and-pypi-after-main--bwrxiw1f3","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,python,crypto,npm","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Socket","item":"https://daily.dev/sources/socketdev"},{"@type":"ListItem","position":3,"name":"Malicious dYdX Packages Published to npm and PyPI After Main..."}]}
```

