Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in btcflip (PyPI)

The btcflip package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was part of the 2026-08-kotanku campaign and has been identified and documented by the OpenSSF.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed the malicious btcflip package
Ecosystems
Attack vectors
Threat actor
Affected entities
  • btcflipPyPI package containing malicious code

The btcflip package distributed via PyPI contained malicious code designed to exfiltrate cryptocurrency wallet files. The malicious behavior was triggered during package import, making it active as soon as the package was installed and imported by a user.

The malicious code was identified as part of the 2026-08-kotanku campaign, which focused on cryptocurrency theft via infostealer functionality. The package communicated with a Telegram bot for command and control purposes.

The incident was documented and credited to the OpenSSF's malicious-packages repository, which tracks known malicious packages across package ecosystems. The malicious package has been identified with hash 2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78.

Indicators of compromise

Packages
  • btcflip
Hashes
  • 2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78

Remediation

  • Immediately uninstall the btcflip package from all systems
  • Audit all systems where btcflip was installed for signs of cryptocurrency wallet compromise
  • Rotate cryptocurrency wallet credentials and keys on affected systems
  • Monitor for unauthorized access to cryptocurrency wallets
  • Review package installation logs to identify all affected users and systems

Sources

  1. GitHub Advisory GHSA-f6qg-475c-wmpp · GitHub Advisory Database

Cite this entry

"Malicious code in btcflip (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 10, 2026; last updated August 10, 2026. https://supplychainattack.org/incident/malicious-code-in-btcflip-pypi-g6motu

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in deepface-weights (PyPI)

    deepface-weights, a malicious package published to PyPI, contains code that exfiltrates Telegram session credentials on import. The package impersonates the legitimate deepface library but contains only credential-stealing functionality.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in reqcrypt (PyPI)

    The reqcrypt PyPI package contains intentionally hidden malicious code that executes arbitrary Python code from attacker-controlled HTTP responses. The PayloadProcessor unconditionally inspects every HTTP response for specific JSON keys and passes base64/gzip/zlib-decoded values to exec(), enabling remote code execution on any system using the library.

    PyPICompromised packageMalicious maintainer
  3. resolvedcritical

    Malicious code in deepface-weight (PyPI)

    The PyPI package deepface-weight contained malicious code that exfiltrated Telegram session files on import, granting attackers full access to associated Telegram accounts. The package was a typosquat of the legitimate deepface ML library with no actual machine-learning functionality.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in infogram-bot (PyPI)

    The infogram-bot package on PyPI contained deliberately malicious code designed to provide remote access, exfiltrate files and credentials, and establish persistence on affected systems. The package was identified as part of the 2026-08-httpz-requests campaign.

    2026 08 Httpz RequestsPyPICompromised package