Malicious code in kotanku (PyPI)
The kotanku package on PyPI contained malicious code that exfiltrates cryptocurrency wallet files upon import. The package was identified as part of a coordinated malicious campaign and has been documented by the OpenSSF.
- Disclosed
- Last updated
- Blast radius
- Any user who installed and imported the kotanku package
- Ecosystems
- Attack vectors
- Affected entities
- kotankuPyPI package containing malicious code
The kotanku package published on PyPI contained malicious code designed to exfiltrate cryptocurrency wallet files. Upon import, the package would execute code to steal wallet data from affected systems.\n\nThe malicious package was identified and attributed to a coordinated campaign (2026-08-kotanku) with clear intent to steal cryptocurrency assets. The attack used a Telegram bot for command and control or data exfiltration.\n\nThe incident was documented by the OpenSSF's malicious-packages repository, which tracks confirmed malicious packages across package ecosystems. The package has been removed from PyPI and the threat is contained.
Indicators of compromise
- Packages
- kotanku
Remediation
- Remove the kotanku package immediately from any systems where it was installed
- Audit systems that imported kotanku for signs of cryptocurrency wallet theft or unauthorized access
- Check cryptocurrency wallets for unauthorized transactions or access
- Review system logs for suspicious network connections to Telegram bot infrastructure
- Use security tools to scan for wallet file exfiltration or data theft
- Monitor accounts and wallets for unauthorized activity
Sources
- GitHub Advisory GHSA-q2fv-xh5f-cfmx · GitHub Advisory Database
Cite this entry
"Malicious code in kotanku (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 9, 2026; last updated August 9, 2026. https://supplychainattack.org/incident/malicious-code-in-kotanku-pypi-1qyu39
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in kb-ai (PyPI)
The kb-ai package on PyPI contained malicious code designed to demonstrate a dependency confusion attack. The package exfiltrated basic system data (IP address, username) and executed arbitrary code during installation via setup.py override.
PyPICompromised packageDependency confusion - resolvedcritical
Malicious code in @years19/n8n-nodes-utils-helper-b (npm)
The npm package @years19/n8n-nodes-utils-helper-b contained malicious code disguised as an n8n workflow utility. The postinstall hook executed reconnaissance, downloaded and extracted a Python tarball with TLS verification disabled, and exfiltrated system information to an attacker-controlled domain.
npmPyPICompromised package - resolvedcritical
Malicious code in @years19/n8n-nodes-utils-helper-c (npm)
The npm package @years19/n8n-nodes-utils-helper-c contained a malicious postinstall script that downloads a trojanized Python multidict module from an attacker-controlled server and injects it into the system's Python site-packages directory, enabling arbitrary code execution on any subsequent Python invocation.
npmPyPICompromised packageMalicious commit - containedcritical
Malicious code in @years19/n8n-nodes-utils-helper-d (npm)
The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.
npmPyPICompromised packageTyposquatting