|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
dYdX は、悪意のある npm/PyPI パッケージを介した深刻なサプライ チェーン攻撃を受けています。脅威、影響、防御戦略を明らかにします。

Security Alert: dYdX Ecosystem Targeted by Malicious npm and PyPI Packages
セキュリティ警告: dYdX エコシステムが悪意のある npm および PyPI パッケージの標的に
In a worrying development for the decentralized finance space, the dYdX ecosystem has become the latest victim of a sophisticated supply chain attack. Threat actors have successfully injected malicious code into dYdX client packages distributed through popular package managers npm and PyPI. This incident, first detected on January 27, 2026, highlights the persistent and evolving threats within the software development lifecycle, particularly for projects handling significant financial volumes.
分散型金融分野の憂慮すべき展開の中で、dYdX エコシステムが高度なサプライチェーン攻撃の最新の犠牲者となっています。脅威アクターは、一般的なパッケージ マネージャー npm および PyPI を通じて配布された dYdX クライアント パッケージに悪意のあるコードを挿入することに成功しました。 2026 年 1 月 27 日に初めて検出されたこのインシデントは、ソフトウェア開発ライフサイクル、特に多額の財務量を扱うプロジェクトにおける持続的かつ進化する脅威を浮き彫りにしています。
The Attack Unveiled
明らかになった攻撃
Cybersecurity firm Socket uncovered the breach, revealing that malicious versions of dYdX client packages were published to both npm and PyPI. The affected npm package, @dydxprotocol/v4-client-js, had compromised versions 3.4.1, 1.22.1, 1.15.2, and 1.0.31. Similarly, the PyPI package dydx-v4-client, version 1.1.5post1, was found to contain malware. These packages are crucial for developers interacting with the dYdX v4 protocol, enabling functions such as transaction signing and wallet management – essential operations for a platform that has facilitated over $1.5 trillion in lifetime trading volume.
サイバーセキュリティ企業 Socket がこの侵害を発見し、悪意のあるバージョンの dYdX クライアント パッケージが npm と PyPI の両方に公開されていたことが明らかになりました。影響を受ける npm パッケージ @dydxprotocol/v4-client-js のバージョン 3.4.1、1.22.1、1.15.2、および 1.0.31 が侵害されました。同様に、PyPI パッケージ dydx-v4-client バージョン 1.1.5post1 にはマルウェアが含まれていることが判明しました。これらのパッケージは、dYdX v4 プロトコルを操作する開発者にとって重要であり、トランザクション署名やウォレット管理などの機能を実現します。これは、生涯取引量が 1 兆 5,000 億ドルを超えるプラットフォームにとって不可欠な操作です。
Malware Mechanics and Impact
マルウェアのメカニズムと影響
The attackers likely gained control of a dYdX maintainer account to push these poisoned packages. In the npm versions, a tampered function, createRegistry(), was designed to steal sensitive information, including seed phrases and device fingerprints, exfiltrating this data to a typosquatted domain, dydx.priceoracle.site. For PyPI users, the malware went a step further, incorporating a Remote Access Trojan (RAT). A function named list_prices() mirrored the data theft seen in the npm package, while an auto-executing payload in _bootstrap.py, obfuscated through multiple decoding layers, allowed attackers to gain deep system access. This RAT could steal SSH keys, API credentials, source code, and even establish backdoors, granting attackers privileged user access.
攻撃者は、これらの汚染されたパッケージをプッシュするために、dYdX メンテナー アカウントの制御を取得した可能性があります。 npm バージョンでは、改ざんされた関数 createRegistry() は、シード フレーズやデバイスのフィンガープリントなどの機密情報を盗み出し、このデータをタイポスクワッティングされたドメイン dydx.priceoracle.site に流出させるように設計されていました。 PyPI ユーザーにとって、このマルウェアはさらに一歩進んで、リモート アクセス トロイの木馬 (RAT) を組み込んでいます。 list_prices() という名前の関数は、npm パッケージで見られたデータ盗難を反映し、複数のデコード層を通じて難読化された _bootstrap.py の自動実行ペイロードにより、攻撃者がシステムに深くアクセスできるようになりました。この RAT は、SSH キー、API 認証情報、ソース コードを盗み、さらにはバックドアを確立して、攻撃者に特権ユーザー アクセスを許可する可能性があります。
The impact is significant, ranging from wallet drains for npm users to full system compromise for PyPI users. Critical infrastructure like trading bots, algorithms, and decentralized applications (dApps) are at high risk if they inadvertently integrated the compromised package versions. This incident follows previous security challenges faced by dYdX, including credential theft in September 2022 and a DNS hijacking incident in July 2024 that led to wallet drains.
その影響は、npm ユーザーのウォレットの流出から PyPI ユーザーのシステム全体の侵害に至るまで、重大です。取引ボット、アルゴリズム、分散型アプリケーション (dApp) などの重要なインフラストラクチャは、侵害されたパッケージ バージョンを誤って統合した場合、高いリスクにさらされます。このインシデントは、2022 年 9 月の資格情報盗難や、ウォレットの枯渇につながった 2024 年 7 月の DNS ハイジャック インシデントなど、dYdX が直面した以前のセキュリティ課題に続くものです。
Mitigation and Future Outlook
緩和と将来の見通し
Socket promptly notified dYdX, which then issued public warnings to isolate systems and rotate credentials. The security firm emphasized that this multi-ecosystem attack underscores the inherent supply chain risks associated with cryptocurrency development tools. Developers are urged to implement rigorous scanning and verification processes for all dependencies.
Socket はただちに dYdX に通知し、dYdX はシステムを隔離し、資格情報をローテーションするよう一般に警告を発しました。セキュリティ会社は、このマルチエコシステム攻撃は、仮想通貨開発ツールに関連する固有のサプライチェーンリスクを浮き彫りにしていると強調した。開発者は、すべての依存関係に対して厳密なスキャンおよび検証プロセスを実装することが求められます。
While the immediate focus is on remediation and strengthening defenses, the incident also casts a shadow over the ongoing discussions about dYdX's tokenomics. Recent analyses suggest a cautious optimism regarding dYdX's price forecast, with expectations of gradual uplift tied to decreased inflation and revenue-sharing initiatives. However, the recent security breach serves as a stark reminder that robust security is paramount and that even well-intentioned tokenomic reforms can be overshadowed by foundational security vulnerabilities. The long-term price projections, which hinge on ecosystem maturity and increased staking participation, will undoubtedly need to account for the ongoing battle against sophisticated cyber threats.
当面の焦点は修復と防御の強化だが、この事件はまた、dYdXのトケノミクスに関する進行中の議論にも影を落としている。最近の分析は、dYdXの価格予測に関して慎重な楽観論を示唆しており、インフレの低下と収益分配の取り組みに関連して緩やかな上昇が期待されています。しかし、最近のセキュリティ侵害は、堅牢なセキュリティが最も重要であり、善意のトークンノミクス改革でさえ、根本的なセキュリティの脆弱性によって影が薄れてしまう可能性があることをはっきりと思い出させてくれます。長期的な価格予測はエコシステムの成熟度やステーキング参加者の増加に左右されるが、間違いなく、高度なサイバー脅威との継続的な戦いを考慮する必要があるだろう。
In the end, staying secure in the fast-paced world of crypto development is like navigating a bustling New York City street – you've got to keep your wits about you, watch out for unexpected detours, and always double-check your routes. Stay vigilant, everyone!
結局のところ、ペースの速い暗号通貨開発の世界で安全を確保することは、ニューヨーク市の賑やかな通りを進むようなものです。機知に富み、予期せぬ迂回路に注意し、ルートを常に再確認する必要があります。皆さんも気をつけてください!
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































