Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Polymarket allegedly paid influencers at least $350,000 for undisclosed promotions: report

June 7, 2026

Ethereum’s RSI Just Hit Its Lowest Level In History, And That May Be Exactly The Point

June 7, 2026

Anome Protocol and 4AIBSC Partner to Scale AI-Powered Applications in Web3

June 7, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New PyPI Malware “Pytoileur” Steals Crypto and Evades Detection
New PyPI Malware “Pytoileur” Steals Crypto and Evades Detection
Security and Privacy

New PyPI Malware “Pytoileur” Steals Crypto and Evades Detection

May 29, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Cybersecurity researchers have uncovered “pytoileur,” a malicious package on the Python Package Index (PyPI). 

The package, posing as an “API Management tool written in Python,” concealed code that downloads and installs trojanized Windows binaries. 

These binaries are capable of surveillance, achieving persistence and stealing cryptocurrency. The package was discovered by Sonatype’s automated malware detection systems and quickly taken down after being flagged.

The pytoileur package, downloaded 264 times before its removal, used deceptive techniques to avoid detection. Its metadata described it as a “Cool package,” using a tactic of labeling packages with appealing, vague descriptions to lure developers into downloading them.

A closer examination, described in an advisory published by Sonatype today, revealed hidden code within the package setup file, obscured by extensive whitespaces. This code executed a base64-encoded payload that retrieved a malicious executable from an external server.

The downloaded binary, “Runtime.exe,” leverages PowerShell and VBScript commands to install itself, ensuring persistence on the infected system. It employs various anti-detection measures to evade analysis by security researchers. 

The binary is capable of information theft and crypto-jacking, targeting user data stored in web browsers and accessing assets associated with cryptocurrency services like Binance and Coinbase, among others.

Further investigation revealed that pytoileur is part of a broader cool package campaign that has been ongoing for months. This campaign involves multiple malicious packages on PyPI, all using similar tactics to download trojanized binaries. 

For instance, packages like “gpt-requests” and “pyefflorer” have been identified as part of this campaign. They employ similar base64 encoding techniques to hide malicious payloads.

Read more on malware targeting cryptocurrency: New Cloud Attack Targets Crypto CDN Meson Ahead of Launch

One package, “lalalaopti,” contained modules designed for clipboard hijacking, keylogging and remote webcam access, indicating the attackers’ broad malicious intent. 

See also  SEC missed a step with its crypto safeguarding rule, U.S. government watchdog says

“This week’s reemergence of an identical malicious Python package is a testament to threat actors reviving and recycling old tactics to cast their net wider and expand their set of targets,” wrote Sonatype.

“[These] often involve developers of several niches (i.e., from AI and machine learning enthusiasts to those relying on popular Python frameworks like Pyston).”

Source link

Crypto detection Evades Malware PyPI Pytoileur Steals
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto Council for Innovation launches coalition to push for regulatory clarity on vaults

June 7, 2026

Greece moves to tax crypto gains at 15% with legislation expected within months

June 7, 2026

Crypto rails made prediction markets global, gambling laws may make them local again

June 7, 2026

Over 80% of EU Crypto Firms Yet to Obtain Full MiCA License Despite Looming Deadline

June 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Why the Crypto Market Is Up Today

July 12, 2023

Kraken relaunches compliant staking for US clients after SEC settlement

January 31, 2025

Validation Cloud launches platform for institutional stakers

November 4, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Polymarket allegedly paid influencers at least $350,000 for undisclosed promotions: report

June 7, 2026

Ethereum’s RSI Just Hit Its Lowest Level In History, And That May Be Exactly The Point

June 7, 2026

Anome Protocol and 4AIBSC Partner to Scale AI-Powered Applications in Web3

June 7, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,512.004.29%
  • ethereumEthereum(ETH)$1,700.048.30%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$606.075.39%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.165.74%
  • solanaSolana(SOL)$66.516.57%
  • tronTRON(TRX)$0.3264330.90%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • HyperliquidHyperliquid(HYPE)$61.358.51%