Malicious code in coinscan (PyPI)
The coinscan package on PyPI (version 0.1.0) contains malicious code that executes encrypted payloads during installation. It fetches an encrypted payload from a suspicious external domain and decrypts it with a hardcoded key, executing the code via exec(). If the network fetch fails, it falls back to a local encrypted payload, ensuring execution even offline. The payload includes sandbox evasion techniques to avoid detection in CI/build environments and targets developer workstations. Additionally, the package uses obfuscation and steganography to hide an infostealer that exfiltrates sensitive data to a command-and-control server referenced via the Polygon blockchain.
AI Analysis
Technical Summary
The coinscan PyPI package (version 0.1.0) contains a malicious dropper that executes encrypted code at install time. It retrieves a JSON manifest from a non-publisher domain, decrypts an encrypted blob using a hardcoded passphrase with PBKDF2 and ChaCha20, and executes the plaintext code. If the network fetch is unsuccessful, it decrypts and executes a fallback payload embedded within the package. The payload checks for environment variables and directories to evade sandbox and CI environments, detonating only on developer workstations. The package also includes obfuscated code that uses steganography to hide an infostealer in an image within a native extension module. This infostealer collects sensitive data and exfiltrates it to a C2 server whose address is dynamically retrieved from the Polygon blockchain transaction history. The combination of encrypted payloads, sandbox evasion, obfuscation, native extensions, and blockchain-based C2 communication represents a sophisticated malicious campaign.
Potential Impact
The malicious code executes arbitrary payloads during package installation, potentially compromising developer workstations by stealing sensitive information. The infostealer embedded in the native extension module can exfiltrate data to a remote command-and-control server, leading to data breaches and further compromise. The sandbox evasion techniques reduce the likelihood of detection during automated analysis, increasing the risk of persistent infection in development environments.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing the coinscan package version 0.1.0 from PyPI. Security teams should block or monitor for this package in their development environments and consider scanning existing environments for its presence. Since the payload executes at install time and includes sandbox evasion, manual inspection and removal of the package and any related artifacts are recommended if detected.
Malicious code in coinscan (PyPI)
Description
The coinscan package on PyPI (version 0.1.0) contains malicious code that executes encrypted payloads during installation. It fetches an encrypted payload from a suspicious external domain and decrypts it with a hardcoded key, executing the code via exec(). If the network fetch fails, it falls back to a local encrypted payload, ensuring execution even offline. The payload includes sandbox evasion techniques to avoid detection in CI/build environments and targets developer workstations. Additionally, the package uses obfuscation and steganography to hide an infostealer that exfiltrates sensitive data to a command-and-control server referenced via the Polygon blockchain.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The coinscan PyPI package (version 0.1.0) contains a malicious dropper that executes encrypted code at install time. It retrieves a JSON manifest from a non-publisher domain, decrypts an encrypted blob using a hardcoded passphrase with PBKDF2 and ChaCha20, and executes the plaintext code. If the network fetch is unsuccessful, it decrypts and executes a fallback payload embedded within the package. The payload checks for environment variables and directories to evade sandbox and CI environments, detonating only on developer workstations. The package also includes obfuscated code that uses steganography to hide an infostealer in an image within a native extension module. This infostealer collects sensitive data and exfiltrates it to a C2 server whose address is dynamically retrieved from the Polygon blockchain transaction history. The combination of encrypted payloads, sandbox evasion, obfuscation, native extensions, and blockchain-based C2 communication represents a sophisticated malicious campaign.
Potential Impact
The malicious code executes arbitrary payloads during package installation, potentially compromising developer workstations by stealing sensitive information. The infostealer embedded in the native extension module can exfiltrate data to a remote command-and-control server, leading to data breaches and further compromise. The sandbox evasion techniques reduce the likelihood of detection during automated analysis, increasing the risk of persistent infection in development environments.
Defensive Guidance
No official patch or remediation is indicated. Users should avoid installing the coinscan package version 0.1.0 from PyPI. Security teams should block or monitor for this package in their development environments and consider scanning existing environments for its presence. Since the payload executes at install time and includes sandbox evasion, manual inspection and removal of the package and any related artifacts are recommended if detected.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17197
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["PyPI"]
Threat ID: 6abb4186f7a7c54106cc2f70
Added to database: 09/29/2026, 04:41:42 UTC
Last enriched: 09/29/2026, 04:46:29 UTC
Last updated: 09/29/2026, 18:13:14 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.