Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in eth-account-wallet (PyPI)

The PyPI package eth-account-wallet contained malicious code that exfiltrated sensitive data during installation, including environment variables, browser data, cryptocurrency wallet files, SSH keys, and credentials. The malicious behavior was triggered via a setup.py install command override.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation prevalence of affected versions
Ecosystems
Attack vectors
Threat actor
Affected entities
  • eth-account-walletPyPI package with malicious install-time code execution

The eth-account-wallet package on PyPI was found to contain malicious code designed to exfiltrate sensitive user data during package installation. The attack was part of a broader 2026-08-bip39-py campaign targeting cryptocurrency-related Python packages.\n\nThe malicious payload was embedded in the package's setup.py file, which overrides the standard install command to execute data-stealing code. During installation, the package exfiltrates environment variables, browser data, cryptocurrency wallet files, SSH keys, and other configuration files from the victim's system.\n\nThe malicious code communicates with a Telegram bot for command and control. The package was identified and reported by the OpenSSF's malicious-packages project, which tracks confirmed malicious software in open-source ecosystems.\n\nUsers who installed affected versions of eth-account-wallet should assume their systems have been compromised and take immediate remediation steps.

Indicators of compromise

Packages
  • eth-account-wallet

Remediation

  • Immediately uninstall eth-account-wallet from all systems
  • Assume compromise of any system where the package was installed
  • Rotate all SSH keys and credentials that may have been exposed
  • Check browser data and cryptocurrency wallet files for unauthorized access or transfers
  • Review environment variables and configuration files for sensitive data exposure
  • Scan systems for persistence mechanisms or additional malware
  • Monitor cryptocurrency accounts for unauthorized transactions
  • Consider this a full system compromise and follow incident response procedures accordingly

Sources

  1. GitHub Advisory GHSA-6xfc-3f4p-8gw6 · GitHub Advisory Database

Cite this entry

"Malicious code in eth-account-wallet (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-eth-account-wallet-pypi-5zdqth

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  2. containedcritical

    Malicious code in reqcrypts (PyPI)

    The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

    2026 08 ReqcryptPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in boto4 (PyPI)

    A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.

    2026 08 Boto4PyPICompromised package
  4. containedcritical

    Malicious code in scrambleeer (PyPI)

    The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.

    2026 08 ScrambleeerPyPICompromised package