Skip to main content

Malicious code in coinscan (PyPI)

0
Critical
Published: 09/27/2026 (09/27/2026, 09:37:17 UTC)
Source: GCVE Database
Product: coinscan

Description

The coinscan package on PyPI (version 0.1.0) contains malicious code that executes encrypted payloads during installation. It fetches an encrypted payload from a suspicious external domain and decrypts it with a hardcoded key, executing the code via exec(). If the network fetch fails, it falls back to a local encrypted payload, ensuring execution even offline. The payload includes sandbox evasion techniques to avoid detection in CI/build environments and targets developer workstations. Additionally, the package uses obfuscation and steganography to hide an infostealer that exfiltrates sensitive data to a command-and-control server referenced via the Polygon blockchain.

Affected software

PyPIghsa
coinscan
Affected versions
=0.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 04:46:29 UTC

Technical Analysis

The coinscan PyPI package (version 0.1.0) contains a malicious dropper that executes encrypted code at install time. It retrieves a JSON manifest from a non-publisher domain, decrypts an encrypted blob using a hardcoded passphrase with PBKDF2 and ChaCha20, and executes the plaintext code. If the network fetch is unsuccessful, it decrypts and executes a fallback payload embedded within the package. The payload checks for environment variables and directories to evade sandbox and CI environments, detonating only on developer workstations. The package also includes obfuscated code that uses steganography to hide an infostealer in an image within a native extension module. This infostealer collects sensitive data and exfiltrates it to a C2 server whose address is dynamically retrieved from the Polygon blockchain transaction history. The combination of encrypted payloads, sandbox evasion, obfuscation, native extensions, and blockchain-based C2 communication represents a sophisticated malicious campaign.

Potential Impact

The malicious code executes arbitrary payloads during package installation, potentially compromising developer workstations by stealing sensitive information. The infostealer embedded in the native extension module can exfiltrate data to a remote command-and-control server, leading to data breaches and further compromise. The sandbox evasion techniques reduce the likelihood of detection during automated analysis, increasing the risk of persistent infection in development environments.

Defensive Guidance

No official patch or remediation is indicated. Users should avoid installing the coinscan package version 0.1.0 from PyPI. Security teams should block or monitor for this package in their development environments and consider scanning existing environments for its presence. Since the payload executes at install time and includes sandbox evasion, manual inspection and removal of the package and any related artifacts are recommended if detected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-17197
Osv Schema Version
1.7.4
Ecosystems
["PyPI"]

Threat ID: 6abb4186f7a7c54106cc2f70

Added to database: 09/29/2026, 04:41:42 UTC

Last enriched: 09/29/2026, 04:46:29 UTC

Last updated: 09/29/2026, 18:13:14 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses