Malicious code in eth-account-wallet (PyPI)
The PyPI package eth-account-wallet contained malicious code that exfiltrated sensitive data during installation, including environment variables, browser data, cryptocurrency wallet files, SSH keys, and credentials. The malicious behavior was triggered via a setup.py install command override.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation prevalence of affected versions
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- eth-account-walletPyPI package with malicious install-time code execution
The eth-account-wallet package on PyPI was found to contain malicious code designed to exfiltrate sensitive user data during package installation. The attack was part of a broader 2026-08-bip39-py campaign targeting cryptocurrency-related Python packages.\n\nThe malicious payload was embedded in the package's setup.py file, which overrides the standard install command to execute data-stealing code. During installation, the package exfiltrates environment variables, browser data, cryptocurrency wallet files, SSH keys, and other configuration files from the victim's system.\n\nThe malicious code communicates with a Telegram bot for command and control. The package was identified and reported by the OpenSSF's malicious-packages project, which tracks confirmed malicious software in open-source ecosystems.\n\nUsers who installed affected versions of eth-account-wallet should assume their systems have been compromised and take immediate remediation steps.
Indicators of compromise
- Packages
- eth-account-wallet
Remediation
- Immediately uninstall eth-account-wallet from all systems
- Assume compromise of any system where the package was installed
- Rotate all SSH keys and credentials that may have been exposed
- Check browser data and cryptocurrency wallet files for unauthorized access or transfers
- Review environment variables and configuration files for sensitive data exposure
- Scan systems for persistence mechanisms or additional malware
- Monitor cryptocurrency accounts for unauthorized transactions
- Consider this a full system compromise and follow incident response procedures accordingly
Sources
- GitHub Advisory GHSA-6xfc-3f4p-8gw6 · GitHub Advisory Database
Cite this entry
"Malicious code in eth-account-wallet (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-eth-account-wallet-pypi-5zdqth
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit - containedcritical
Malicious code in boto4 (PyPI)
A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.
2026 08 Boto4PyPICompromised package - containedcritical
Malicious code in scrambleeer (PyPI)
The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.
2026 08 ScrambleeerPyPICompromised package