Velora identifies and unpublishes malicious npm package version in supply chain attack targeting its DEX aggregator SDK


4 recorded changes
Want your article here?
Promote with Leviathan News

4 recorded changes
Want your article here?
Promote with Leviathan NewsVelora, a decentralized exchange (DEX) aggregator project, disclosed that one of the npm package versions used for its SDK had been compromised in an npm supply chain attack and that it identified and unpublished the malicious version. The incident is part of a wider wave of critical npm and PyPI compromises in 2025β2026 that use backdoored package versions to steal credentials and spread through developer tooling.
AI-generated background, compiled from web sources β not editorial content.

π/@FabianoSolana Β·

π/@k06a Β·

π/@DefiLlama Β·

π/@dominic_w Β·

π/@AlliumLabs Β·

blog.availproject.org Β·

π/@FabianoSolana Β·

π/@k06a Β·

π/@DefiLlama Β·

π/@dominic_w Β·

π/@AlliumLabs Β·

blog.availproject.org Β·
π Love DeFi? Ready to dive in and start earning $SQUID while making an impact?