Malicious code in yfniance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
- Disclosed
- Last updated
- Blast radius
- 900+ malicious packages distributed via PyPI
- Ecosystems
- Attack vectors
- Affected entities
- yfniancePyPI package
An attacker distributed over 900 malicious packages via the Python Package Index (PyPI), with yfniance being one of the identified packages. The malicious code installed browser extensions on infected systems with the capability to intercept and manipulate clipboard contents and replace cryptocurrency wallet addresses, enabling theft of cryptocurrency transactions.\n\nThe attack was identified and documented by Checkmarx, with credit to the OpenSSF's malicious-packages repository for tracking and cataloging the incident. The malicious packages were distributed through the official PyPI repository, making them accessible to any Python developer using standard package installation tools.\n\nThis represents a significant supply chain attack targeting cryptocurrency users and developers, leveraging the trust placed in the PyPI ecosystem to distribute malware at scale.
Indicators of compromise
- Packages
- yfniance
Remediation
- Immediately uninstall yfniance and any other packages from the 900+ malicious package list from affected systems
- Audit pip package installation history to identify if any malicious packages were installed
- Remove any suspicious browser extensions, particularly those installed around the time of package installation
- Reset cryptocurrency wallet addresses and review transaction history for unauthorized transfers
- Update all cryptocurrency wallet software and enable additional security measures such as hardware wallet usage
- Review and strengthen Python package management practices, including using dependency pinning and verification of package sources
Sources
- GitHub Advisory GHSA-frrx-r6wq-6pp2 · GitHub Advisory Database
Cite this entry
"Malicious code in yfniance (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-yfniance-pypi-jwmtlj
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package