Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Kotanku supply chain incidents

3 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in kotoraka (PyPI)

    The kotoraka package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files during import. The package was part of a coordinated malicious campaign (2026-08-kotanku) and has been identified and cataloged by the OpenSSF.

    2026 08 KotankuPyPICompromised package
  2. containedcritical

    Malicious code in btcflip (PyPI)

    The btcflip package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was part of the 2026-08-kotanku campaign and has been identified and documented by the OpenSSF.

    2026 08 KotankuPyPICompromised package
  3. containedcritical

    Malicious code in btcflx (PyPI)

    The btcflx package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was part of the 2026-08-kotanku campaign and has been identified and reported by the OpenSSF.

    2026 08 KotankuPyPICompromised package