Velora, a decentralized exchange (DEX) aggregator project, disclosed that one of the npm package versions used for its SDK had been compromised in an npm supply chain attack and that it identified and unpublished the malicious version. The incident is part of a wider wave of critical npm and PyPI compromises in 2025–2026 that use backdoored package versions to steal credentials and spread through developer tooling.

AI-generated background, compiled from web sources β€” not editorial content.

More coverage

Explore the topic

More on DEX

Comments