Open source packages published on the npm and PyPI repositories were laced with code that stole wallet credentials from dYdX ...