Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Exclusive Binance’s SB Seker on India's INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Exclusive: Binance’s SB Seker on India’s INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Crypto Tools Under Attack as Apifox Breach Exposes Sensitive Data

Apifox and LiteLLM supply chain attacks expose credentials, cloud systems, and crypto tools, highlighting rising global security risks.

Written By Kenrodgers Fabian
Fact Checked by Dishita Malvania
Published 2026-03-26·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
Crypto Tools Under Attack as Apifox Breach Exposes Sensitive Data

Key Highlights

  • Apifox CDN attacks let hidden code steal tokens, credentials, and run remote commands on infected systems.
  • LiteLLM PyPI breach may have exposed 300GB of data and 500K credentials across cloud and developer tools.
  • Researchers warn supply chain attacks now target crypto and cloud tools using stolen keys and infrastructure access.

A major security scare has emerged after researchers uncovered a supply chain attack targeting the Apifox desktop client, an API development platform. According to SlowMist, attackers were able to compromise an official CDN-hosted script, slipping malicious code into what appeared to be a trusted analytics file. Because Apifox runs on Electron, the infected script executed automatically across users’ systems worldwide—without any action required.

Once active, the malware silently harvested sensitive data, including login tokens, system information, and API credentials, and transmitted it to attacker-controlled servers. Even more concerning, it enabled remote code execution, effectively giving attackers the ability to access and control affected machines in the background.

🚨 Security Alert: Supply Chain Attack on Apifox Desktop Client

Yesterday, we detected a supply chain attack in which a front-end script file hosted on #Apifox’s official CDN was injected with heavily obfuscated malicious JavaScript code.

⚡ Impact on Apifox Desktop Client… pic.twitter.com/Z8Sl8FgFjQ

— SlowMist (@SlowMist_Team) March 26, 2026

The case reflects a wider pattern of similar attacks seen recently across crypto and cloud development tools.

Apifox CDN injection and data theft mechanics

The attack reportedly started when the official Apifox CDN script file was tampered with. Because the desktop app is built on Electron, it automatically loads this script every time it starts and during normal use, which allows the malicious code to run without any user action.

Upon entering, this code was heavily disguised to prevent detection. Various methods, including obfuscation, RC4 encryption for hiding texts, and complex calculations, were used to prevent security software and experts from understanding what this code was doing.

In addition to this, communication with a command server outside the network was established. This is called “beaconing.” By doing this, the malware sent out information repeatedly and thus allowed for data theft over time.

Meanwhile, communication between this infected computer and the server belonging to the attackers is encrypted using RSA. While this ensures security for the information being sent, it also makes it more difficult for experts to trace and analyze what is being sent.

LiteLLM breach and wider crypto supply chain risks

In a separate case, security researchers recently reported a breach involving LiteLLM after malicious code was added to PyPI package versions 1.82.7 and 1.82.8. The compromised updates are believed to have exposed a large amount of sensitive data, including roughly 300GB of information and about 500,000 user credentials worldwide.

As a result, developers and organizations may have been put at risk across multiple systems, including SSH keys and cloud services such as AWS, Google Cloud, Azure, as well as Kubernetes and database environments. These credentials could potentially allow attackers deeper access into the affected infrastructure.

In a similar vein, the chief security researcher at SlowMist, 23pds, called on the developers to act fast by checking the system, replacing all relevant keys and credentials, and checking the logs for signs of compromise, stating that failure to act fast might lead to dire consequences, as seen in the past, including the breach experienced by the Trust Wallet team.

In addition, security researchers have earlier linked some of these activities to North Korea-associated threat campaigns targeting crypto platforms and exchange service providers. According to the reports, attackers have been using stolen AWS credentials, Terraform configurations, Docker images, and Kubernetes clusters to gain deeper access into systems.

The incidents underline growing risks in software supply chains, showing how easily attackers can exploit trusted tools and services. Organizations need to carefully review the third-party libraries and dependencies they rely on and keep a close eye on the integrity of scripts and files pulled from CDNs.

Also Read: Balancer Labs Shuts Down: Protocol Pivots to DAO After $128M Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

IREN Stock Climbs Ahead of Earnings as AI Cloud Business Expands
IREN Stock Climbs Ahead of Earnings as AI Cloud Business Expands
Ripple’s RLUSD Tops $2B as Stablecoin Supply Nears $1B on XRPL
Ripple’s RLUSD Tops $2B as Stablecoin Supply Nears $1B on XRPL
Japan Weighs Blockchain-Based Settlement for Stocks, Government Bonds
Japan Weighs Blockchain-Based Settlement for Stocks, Government Bonds
Bitwise Debuts Automated Portfolios With Coinbase Tokenized Stocks
Bitwise Debuts Automated Portfolios With Coinbase Tokenized Stocks
Onafriq Integrates Circle’s USDC Across 40+ African Markets
Onafriq Integrates Circle’s USDC Across 40+ African Markets

Find Us on Socials

You may also like

White Lisk logo next to a stack of blue LSK coins surrounded by glowing embers and flames

Lisk Proposes Shutting Down Its DAO and Burning 100M LSK

Smartphone displaying Kylie Jenner’s X profile alongside a Solana coin and a sharp market crash chart

Kylie Jenner’s X Account Allegedly Hacked to Promote $KYLIE Token, Market Cap Crashes 90%

A hooded hacker sitting before multiple screens showing volatile red and green candlestick charts

Morpho’s 15-Minute TWAP Oracle Exploited in $36.39M Liquidation Attack

Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses

Galaxy Finds $115M Lost in Coldcard Exploit Across 8,865 Addresses

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information