Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

SEC’s big swing to clear tokenization path isn’t likely to get resilience of full rule

June 15, 2026

Hyperliquid – HYPE has ONE hurdle before $72-$74 comes into view

June 15, 2026

Da Vinci Recognized as a Notable Vendor in Q2 2026 Forrester Warehouse Management Systems Landscape

June 15, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Malicious PyPI Package Exposes Crypto Wallets to Infostealer Code
Malicious PyPI Package Exposes Crypto Wallets to Infostealer Code
Security and Privacy

Malicious PyPI Package Exposes Crypto Wallets to Infostealer Code

November 28, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A malicious Python Package Index (PyPI) package, dubbed “aiocpa” and engineered to steal cryptocurrency wallet data, has been uncovered by security researchers. 

The package posed as a legitimate crypto client tool while secretly exfiltrating sensitive information to a Telegram bot. Reversing Labs researchers identified and reported the threat, leading to its removal from the PyPI.

Discovered on November 21, aiocpa evaded traditional security checks by publishing authentic-looking updates to an initially benign tool. Obfuscated code within the utils/sync.py file revealed a wrapper around the CryptoPay initialization function, designed to extract tokens and other sensitive data. 

Further analysis showed that this code used layers of Base64 encoding and zlib compression to hide its malicious intent.

Unlike many attacks targeting open-source repositories, the creators of aiocpa avoided impersonation tactics. Instead, they built a user base by presenting the package as a legitimate tool. 

“A first glance at the package’s project page didn’t show any reason for suspicion. It looked like a well-maintained crypto-pay API client package, with several versions published since September 2024. It also had a well-organized documentation page,” Reversing Labs explained.

The researchers also noted an attempt to take over an existing PyPI project, “pay,” to exploit its established user base.

Lessons for Developers

Reversing Labs further warned that the aiocpa incident highlights critical steps developers should take to secure their software:

  • Pin dependencies and versions to prevent unexpected updates

  • Use hash checks to verify package integrity

  • Perform advanced security assessments using behavioral analysis tools

Read more on software supply threats: CISA Urges Improvements in US Software Supply Chain Transparency

“This incident is a clear reminder that open-source software security threats are growing and becoming harder to detect,” Reversing Labs said.

See also  TeamTNT Targeted Cloud Instances and Containerized Environments For Two Years

The firm also stated that the measures employed by the threat actors to conceal their malicious creation made it difficult to identify the supply chain threat, even with diligent attempts to evaluate the quality and integrity of the package.

“With the ever-growing sophistication of threat actors and the complexity of modern software supply chains, dedicated tools need to be incorporated into your development process to help prevent these threats and mitigate related risks.”

Source link

code Crypto Exposes Infostealer Malicious Package PyPI wallets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

White House Targets July 4 Deadline for U.S. Crypto Market Structure Bill

June 15, 2026

Congress moves to rebuild crypto crime task force after DOJ dismantled its dedicated crypto team

June 15, 2026

CLARITY Act Brings Certainty, Protection, and Integrity to Crypto Markets

June 15, 2026

Zimbabwe Ends Crypto Legal Gray Zone with First Mandatory Registration Rules

June 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

JPMorgan, Apollo Tokenize Funds in ‘Proof of Concept’ With Axelar, Oasis, Provenance

November 16, 2023

Hacking Incident With OKX Crypto Users Is Now Getting More Intense

June 15, 2024

Former President Donald Trump Holds $250,000 In ETH, Financial Report Discloses

August 12, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

SEC’s big swing to clear tokenization path isn’t likely to get resilience of full rule

June 15, 2026

Hyperliquid – HYPE has ONE hurdle before $72-$74 comes into view

June 15, 2026

Da Vinci Recognized as a Notable Vendor in Q2 2026 Forrester Warehouse Management Systems Landscape

June 15, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$66,368.001.67%
  • ethereumEthereum(ETH)$1,813.775.57%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$619.420.71%
  • rippleXRP(XRP)$1.256.89%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$74.526.20%
  • tronTRON(TRX)$0.3197940.27%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.28%
  • HyperliquidHyperliquid(HYPE)$67.677.32%