Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys

bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown—depends on installation count during 48-hour availability window
Ecosystems
Attack vectors
Affected entities
  • bittensor-wallet · 4.0.2

On March 17, 2026, bittensor-wallet version 4.0.2 was identified as a compromised PyPI package containing a backdoor designed to exfiltrate private keys. The malicious release had been live on PyPI for approximately 48 hours before being removed (yanked).

The backdoor was discovered through a direct technical diff of the source tarballs for versions 4.0.1 and 4.0.2, revealing exactly what changes were introduced in the malicious release. Analysis by StepSecurity captured command and control (C2) channels communicating in real time when the compromised package was executed.

The package has since been yanked from PyPI, containing the incident. However, any systems that installed bittensor-wallet 4.0.2 during the 48-hour window of availability may be affected, and users should be advised to audit systems and rotate credentials.

Indicators of compromise

Packages
  • bittensor-wallet==4.0.2

Remediation

  • Immediately remove bittensor-wallet 4.0.2 from all systems and downgrade to version 4.0.1 or earlier
  • Rotate any private keys or credentials that may have been present on systems running the compromised version
  • Audit logs for C2 communication or suspicious network activity associated with the backdoor
  • Verify that PyPI or your artifact repository is configured to prevent installation of yanked packages
  • Review installation logs to identify any systems that may have downloaded the compromised package during the 48-hour exposure window

Sources

  1. bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys · StepSecurity

Cite this entry

"bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 17, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/bittensor-wallet-4-0-2-compromised-on-pypi-backdoor-exfiltrates-private-keys-2b196w

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

    PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adv2099m2 (PyPI)

    Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in adminbypasser (PyPI)

    Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in adpaypal (PyPI)

    The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package