Malicious code in btcflx (PyPI)
The PyPI package 'btcflx' version 0.1.0 is a malicious library that, upon import, searches for Monero cryptocurrency wallet directories on the user's system, terminates related processes to unlock files, archives the wallet data, and exfiltrates it to a hardcoded Telegram bot. The package disguises itself as an HTTP speed-up library, misleading users about its true intent. It also sends status messages about the wallet discovery to the same Telegram bot. This behavior constitutes clear malicious activity aimed at stealing cryptocurrency wallet data.
AI Analysis
Technical Summary
The 'btcflx' PyPI package (version 0.1.0) masquerades as an HTTP speed-up library but contains embedded malicious code that activates upon import. It unconditionally locates Monero wallet directories on Windows and Linux systems, kills running 'feather' and 'monero' processes to release file locks on wallet files, archives the wallet directory, and uploads the archive to a Telegram bot via the Telegram API. The Telegram bot token and target paths are base64-encoded in the source code to obfuscate the exfiltration destination and targets. Additionally, the package sends reconnaissance status messages to the same Telegram bot. The package name and description do not mention cryptocurrency wallets, creating a cover-story mismatch to evade suspicion.
Potential Impact
Users who install and import the 'btcflx' package version 0.1.0 risk having their Monero cryptocurrency wallet files stolen. The malicious code forcibly terminates wallet-related processes to access locked files, then archives and exfiltrates sensitive wallet data to an attacker-controlled Telegram bot. This leads to a direct compromise of cryptocurrency assets stored in the affected wallets. There is no indication of broader system compromise beyond wallet data theft.
Mitigation Recommendations
No official patch or remediation is currently available for this malicious package. Users should immediately uninstall 'btcflx' version 0.1.0 and avoid importing it in any environment. Verify that no unauthorized Telegram bot tokens or suspicious network activity related to Telegram API calls exist on affected systems. Use trusted sources and verify package integrity before installation. Consider scanning for and removing any archived wallet data that may have been exfiltrated. Monitor for updates from PyPI or security advisories regarding this package.
Malicious code in btcflx (PyPI)
Description
The PyPI package 'btcflx' version 0.1.0 is a malicious library that, upon import, searches for Monero cryptocurrency wallet directories on the user's system, terminates related processes to unlock files, archives the wallet data, and exfiltrates it to a hardcoded Telegram bot. The package disguises itself as an HTTP speed-up library, misleading users about its true intent. It also sends status messages about the wallet discovery to the same Telegram bot. This behavior constitutes clear malicious activity aimed at stealing cryptocurrency wallet data.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'btcflx' PyPI package (version 0.1.0) masquerades as an HTTP speed-up library but contains embedded malicious code that activates upon import. It unconditionally locates Monero wallet directories on Windows and Linux systems, kills running 'feather' and 'monero' processes to release file locks on wallet files, archives the wallet directory, and uploads the archive to a Telegram bot via the Telegram API. The Telegram bot token and target paths are base64-encoded in the source code to obfuscate the exfiltration destination and targets. Additionally, the package sends reconnaissance status messages to the same Telegram bot. The package name and description do not mention cryptocurrency wallets, creating a cover-story mismatch to evade suspicion.
Potential Impact
Users who install and import the 'btcflx' package version 0.1.0 risk having their Monero cryptocurrency wallet files stolen. The malicious code forcibly terminates wallet-related processes to access locked files, then archives and exfiltrates sensitive wallet data to an attacker-controlled Telegram bot. This leads to a direct compromise of cryptocurrency assets stored in the affected wallets. There is no indication of broader system compromise beyond wallet data theft.
Defensive Guidance
No official patch or remediation is currently available for this malicious package. Users should immediately uninstall 'btcflx' version 0.1.0 and avoid importing it in any environment. Verify that no unauthorized Telegram bot tokens or suspicious network activity related to Telegram API calls exist on affected systems. Use trusted sources and verify package integrity before installation. Consider scanning for and removing any archived wallet data that may have been exfiltrated. Monitor for updates from PyPI or security advisories regarding this package.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13682
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6a79f0dbbf8831d539f618b7
Added to database: 08/10/2026, 15:40:11 UTC
Last enriched: 08/10/2026, 15:58:46 UTC
Last updated: 09/23/2026, 03:43:38 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.