Skip to content

Commit 6d2a1e3

Browse files
authored
Update software-supply-chain-attacks-crypto.md
1 parent 0318ba8 commit 6d2a1e3

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

software-supply-chain-attacks-crypto.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -202,6 +202,10 @@ The attacked Python package is bitcoinlib, a popular Python library that contain
202202

203203
Source: <https://www.reversinglabs.com/blog/malicious-python-packages-target-popular-bitcoin-library>
204204

205+
### 23. Malicious NuGet Packages
206+
207+
[Malicious NuGet Packages Typosquat Nethereum to Exfiltrate Wallet Keys](https://socket.dev/blog/malicious-nuget-packages-typosquat-nethereum-to-exfiltrate-wallet-keys) by Kirill Boychenko (Socket).
208+
205209
## Hardware supply chain attacks
206210

207211
It is possible to tamper with hardware devices used in crypto, typically a hardware wallet. Who would do that: an employee at the company that designed the wallet, the factory that produced it, and everyone involved in shipping it. Ref: <https://vitalik.ca/general/2021/01/11/recovery.html>. Such a real hardware supply chain attack has happened on Trezor wallets (2022): <https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/>

0 commit comments

Comments
 (0)