2026 08 Kotanku supply chain incidents
3 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.
- containedcritical
Malicious code in kotoraka (PyPI)
The kotoraka package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files during import. The package was part of a coordinated malicious campaign (2026-08-kotanku) and has been identified and cataloged by the OpenSSF.
2026 08 KotankuPyPICompromised package - containedcritical
Malicious code in btcflip (PyPI)
The btcflip package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was part of the 2026-08-kotanku campaign and has been identified and documented by the OpenSSF.
2026 08 KotankuPyPICompromised package - containedcritical
Malicious code in btcflx (PyPI)
The btcflx package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was part of the 2026-08-kotanku campaign and has been identified and reported by the OpenSSF.
2026 08 KotankuPyPICompromised package