← Back to Delta Incident Archive

VERIFIED SECURITY INCIDENT · DCI-2026-009

Malicious npm package supply-chain campaign

At least 30 lookalike Web3 packages carried credential-stealing code; aggregate wallet losses were not publicly established.

Incident date2026-07-01 Attack typeSupply-chain attack SeverityMedium Involved chainsOther

Incident overview

At least 30 lookalike Web3 packages carried credential-stealing code; aggregate wallet losses were not publicly established.

Amount basis

No single verified USD loss figure was published; see the incident record.

Evidence boundary

The archive preserves the publicly reported cause, sequence, asset-flow status, and evidence boundaries. Attribution or downstream movement not established by the cited sources remains unconfirmed.