Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Bip39 PY supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in eth-account-wallet (PyPI)

    The PyPI package eth-account-wallet contained malicious code that exfiltrated sensitive data during installation, including environment variables, browser data, cryptocurrency wallet files, SSH keys, and credentials. The malicious behavior was triggered via a setup.py install command override.

    2026 08 Bip39 PYPyPICompromised package