Malicious code in btcflip (PyPI)
The btcflip package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was part of the 2026-08-kotanku campaign and has been identified and documented by the OpenSSF.
- Disclosed
- Last updated
- Blast radius
- All users who installed the malicious btcflip package
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- btcflipPyPI package containing malicious code
The btcflip package distributed via PyPI contained malicious code designed to exfiltrate cryptocurrency wallet files. The malicious behavior was triggered during package import, making it active as soon as the package was installed and imported by a user.
The malicious code was identified as part of the 2026-08-kotanku campaign, which focused on cryptocurrency theft via infostealer functionality. The package communicated with a Telegram bot for command and control purposes.
The incident was documented and credited to the OpenSSF's malicious-packages repository, which tracks known malicious packages across package ecosystems. The malicious package has been identified with hash 2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78.
Indicators of compromise
- Packages
- btcflip
- Hashes
- 2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78
Remediation
- Immediately uninstall the btcflip package from all systems
- Audit all systems where btcflip was installed for signs of cryptocurrency wallet compromise
- Rotate cryptocurrency wallet credentials and keys on affected systems
- Monitor for unauthorized access to cryptocurrency wallets
- Review package installation logs to identify all affected users and systems
Sources
- GitHub Advisory GHSA-f6qg-475c-wmpp · GitHub Advisory Database
Cite this entry
"Malicious code in btcflip (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 10, 2026; last updated August 10, 2026. https://supplychainattack.org/incident/malicious-code-in-btcflip-pypi-g6motu
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in deepface-weights (PyPI)
deepface-weights, a malicious package published to PyPI, contains code that exfiltrates Telegram session credentials on import. The package impersonates the legitimate deepface library but contains only credential-stealing functionality.
PyPICompromised package - resolvedcritical
Malicious code in reqcrypt (PyPI)
The reqcrypt PyPI package contains intentionally hidden malicious code that executes arbitrary Python code from attacker-controlled HTTP responses. The PayloadProcessor unconditionally inspects every HTTP response for specific JSON keys and passes base64/gzip/zlib-decoded values to exec(), enabling remote code execution on any system using the library.
PyPICompromised packageMalicious maintainer - resolvedcritical
Malicious code in deepface-weight (PyPI)
The PyPI package deepface-weight contained malicious code that exfiltrated Telegram session files on import, granting attackers full access to associated Telegram accounts. The package was a typosquat of the legitimate deepface ML library with no actual machine-learning functionality.
PyPICompromised package - resolvedcritical
Malicious code in infogram-bot (PyPI)
The infogram-bot package on PyPI contained deliberately malicious code designed to provide remote access, exfiltrate files and credentials, and establish persistence on affected systems. The package was identified as part of the 2026-08-httpz-requests campaign.
2026 08 Httpz RequestsPyPICompromised package