Velora discovered and unpublished a malicious npm package version targeting its DEX aggregator SDK in a supply chain attack.
Security & Exploits ·
Velora identified and unpublished a malicious version of its DEX aggregator SDK package after detecting a supply chain attack. The incident affected @velora-dex/sdk@9.4.1, which was removed from distribution, though the version remains visible in npm's historical records pending removal by the package manager. The compromise was contained to the SDK release alone with no evidence of compromise elsewhere in the project's infrastructure or systems.
Developers are advised to avoid installing or upgrading to the affected version while Velora completes its investigation and prepares a confirmed safe update. The malicious publish was limited in scope to that single SDK release, reducing the surface of potential exposure.
The exact nature of the malicious code, how many systems or developers may have installed the compromised version, and the timeline for a patched release remain unknown. Velora indicated further updates would be shared as cleanup steps continue.