Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 04 Tronix supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in trongriden (PyPI)

    Malicious package trongriden published to PyPI designed for private key exfiltration, part of a broader 2025-04-tronix campaign targeting cryptocurrency users. No known usage has been reported.

    2025 04 TronixPyPICompromised package