Malicious code in yyfinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
- Disclosed
- Last updated
- Blast radius
- 900+ malicious packages distributed via PyPI
- Ecosystems
- Attack vectors
- Affected entities
- yyfinanceMalicious package distributed via PyPI
A large-scale malicious package campaign distributed over 900 compromised packages through the Python Package Index (PyPI). The yyfinance package was among those affected by this attack.\n\nThe malicious code installed a browser extension that performed clipboard manipulation and cryptocurrency wallet address replacement attacks. This technique targets users who copy and paste wallet addresses, replacing them with attacker-controlled addresses to redirect cryptocurrency transactions.\n\nThe attack was identified and documented by Checkmarx and credited to the OpenSSF's malicious-packages repository. The incident represents a significant supply chain compromise affecting the Python ecosystem.
Indicators of compromise
- Packages
- yyfinance
Remediation
- Remove or uninstall the yyfinance package immediately if installed
- Scan systems for the malicious browser extension and remove it
- Review browser extensions for any suspicious or unfamiliar additions
- Check cryptocurrency wallet addresses in clipboard history for signs of manipulation
- Update to a clean version of any legitimate package from a trusted source
- Monitor for unauthorized cryptocurrency transactions
- Consider using hardware wallets or address verification mechanisms to prevent clipboard replacement attacks
Sources
- GitHub Advisory GHSA-7rhm-vjwr-qmrp · GitHub Advisory Database
Cite this entry
"Malicious code in yyfinance (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-yyfinance-pypi-129884
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in riakcs (PyPI)
The riakcs package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package