MAL-2026-13681Malicious code in btcflip (PyPI)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
0.1.0 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| PyPI | btcflip | 0.1.0 |
{"schema_version":"1.7.4","id":"MAL-2026-13681","published":"2026-08-10T05:21:14Z","modified":"2026-08-10T11:53:52.176444450Z","summary":"Malicious code in btcflip (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e4271f738e49ead6113a249ca949232cad9664db210319a097b56385b1942970)\nThe package advertises itself as an HTTP speed-up library, but on import it archives the user's Monero wallet directory (C:\\Users\\<user>\\Documents\\Monero on Windows, /home/<user>/Monero on Linux) and uploads the archive to a hardcoded Telegram bot via api.telegram.org/bot<token>/sendDocument (chat_id -5044692933). The destination bot token and wallet paths are stored as base64 blobs (constants TK, XMR_WIN, XMR_LINUX) and decoded at runtime to conceal the exfiltration target. The exfil routine is invoked at module top level, so any `import btcflip` (which loads the inner `kotoraka` module) triggers wallet theft. The code also terminates feather/monero processes to release file locks before archiving. The stated purpose of the package is unrelated to Monero wallets and is a cover story for wallet theft.\n\n## Source: kam193 (2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78)\nDuring import, the package exfiltrates cryptocurrency wallet files.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-08-kotanku\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-crypto\n\n\n - uses-telegram-bot\n","affected":[{"package":{"name":"btcflip","ecosystem":"PyPI"},"versions":["0.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"kotoraka/__init__.py","sha256":"1f9b92b37899ca0f6f2edbffb3fa425a43e8927256f04fb5966be265b08bd8e2","tlsh":"a351f24ede6a440451b1938e2dc194b2c705326b6e10952f7ebc4a80afb08a6d672b7f"}],"package_integrity":[{"filename":"btcflip-0.1.0-py3-none-any.whl","hashes":{"blake2b_256":"f25eb14e2b94ecfc3fe598595f7edb4bec462c4b279ed0e88e70ff31307e6aed","md5":"cddecd603b55b8fbd272de0732d27a10","sha256":"04f93b85bc9d1ef85e7ee9eb581f5c20c63c760e4c6e460473934426a70575e7"}},{"filename":"btcflip-0.1.0.tar.gz","hashes":{"blake2b_256":"22bafc8d72f8cc8d32eb258b28c03cce912d641942fb8e0eb4db6160eb9837d8","md5":"5c889271d9dc0b34715359963a907312","sha256":"a7c84dafeec36de00cfacfb73b0e7d74f00c509581a41e5a604b810a90ef68d2"}}]}}}],"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/btcflip"},{"type":"PACKAGE","url":"https://pypi.org/project/btcflip/0.1.0/"}],"database_specific":{"malicious-packages-origins":[{"id":"pypi/2026-08-kotanku/btcflip","import_time":"2026-08-10T06:38:36.536152009Z","modified_time":"2026-08-10T05:21:14.020182Z","sha256":"2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78","source":"kam193","versions":["0.1.0"]},{"id":"IN-MAL-2026-017210","import_time":"2026-08-10T11:51:55.15387373Z","modified_time":"2026-08-10T11:50:48Z","sha256":"e4271f738e49ead6113a249ca949232cad9664db210319a097b56385b1942970","source":"amazon-inspector","versions":["0.1.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0