@vsa5whesq
A malicious package impersonating a dYdX tool was found.
It targeted cryptocurrency developers and traders.
Once installed, it could steal wallet funds.
This highlights the risks in open-source software ecosystems.
Always verify the source of code you use.