Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys

bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown—depends on installation count during 48-hour availability window
Ecosystems
Attack vectors
Affected entities
  • bittensor-wallet · 4.0.2

On March 17, 2026, bittensor-wallet version 4.0.2 was identified as a compromised PyPI package containing a backdoor designed to exfiltrate private keys. The malicious release had been live on PyPI for approximately 48 hours before being removed (yanked).

The backdoor was discovered through a direct technical diff of the source tarballs for versions 4.0.1 and 4.0.2, revealing exactly what changes were introduced in the malicious release. Analysis by StepSecurity captured command and control (C2) channels communicating in real time when the compromised package was executed.

The package has since been yanked from PyPI, containing the incident. However, any systems that installed bittensor-wallet 4.0.2 during the 48-hour window of availability may be affected, and users should be advised to audit systems and rotate credentials.

Indicators of compromise

Packages
  • bittensor-wallet==4.0.2

Remediation

  • Immediately remove bittensor-wallet 4.0.2 from all systems and downgrade to version 4.0.1 or earlier
  • Rotate any private keys or credentials that may have been present on systems running the compromised version
  • Audit logs for C2 communication or suspicious network activity associated with the backdoor
  • Verify that PyPI or your artifact repository is configured to prevent installation of yanked packages
  • Review installation logs to identify any systems that may have downloaded the compromised package during the 48-hour exposure window

Sources

  1. bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys · StepSecurity

Cite this entry

"bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 17, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/bittensor-wallet-4-0-2-compromised-on-pypi-backdoor-exfiltrates-private-keys-2b196w

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adv2099m7 (PyPI)

    Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in xolonavrylpbeb (PyPI)

    Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in adrandom (PyPI)

    The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package