Monkey-Patched PyPI Packages Use Transitive Dependencies to Steal Solana Private Keys
Socket’s Threat Research Team uncovered a supply chain attack on the Python Package Index (PyPI), orchestrated by a threat actor using the alias cappership. The threat actor embedded a covert key‑s...