Malicious code in trongriden (PyPI)
Malicious package trongriden published to PyPI designed for private key exfiltration, part of a broader 2025-04-tronix campaign targeting cryptocurrency users. No known usage has been reported.
- Disclosed
- Last updated
- Blast radius
- Unknown; no known usage reported
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- trongridenPyPI package designed for private key exfiltration
The PyPI package trongriden was identified as malicious by the OpenSSF malicious-packages project. The package appears designed to exfiltrate private keys, with a name referencing the TRX (Tron/Tronix) cryptocurrency, suggesting it targets cryptocurrency users.
The package is part of a broader campaign (2025-04-tronix) involving similar malicious packages repeatedly uploaded to PyPI. Some packages in this campaign clone the README files of legitimate libraries to increase credibility and evade detection.
While the package exhibits clear malicious intent consistent with infostealer malware, no confirmed usage or compromise has been reported at this time. The package has been identified and cataloged by the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- trongriden
Remediation
- Remove trongriden from any Python environments where it may have been installed
- Audit pip install logs and dependency manifests for any reference to trongriden
- If trongriden was installed, assume private keys and credentials may be compromised; rotate all cryptocurrency wallets, API keys, and sensitive credentials
- Monitor PyPI for similar package names in the 2025-04-tronix campaign and block them at the package manager level
- Use pip audit or similar tools to detect malicious packages in your supply chain
Sources
- GitHub Advisory GHSA-fgg6-xq4r-cp2h · GitHub Advisory Database
Cite this entry
"Malicious code in trongriden (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 2, 2026; last updated August 2, 2026. https://supplychainattack.org/incident/malicious-code-in-trongriden-pypi-1rex6c
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in wacve-utils (PyPI)
The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.
PyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.
PyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-ai-platform (PyPI)
The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - containedhigh
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.
PyPICompromised package