Threats Tagged 'mal-2026-16129'
View all threats tagged with 'mal-2026-16129'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-16129'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (19e3eadaccc63a1e12d0e3cfe153cbf78e114f30285d4da3694990827e5f5c5a) The package `web3-eth-account` typosquats the legitimate `eth-account` library and copies its metadata (ApeWorX/ethereum.org author addresses, README instructing `pip install eth-account`). On `import eth_account`, `__init__.py` calls `_auto()` which, when the environment variables `ETH_ACCT_RPC` and `ETH_ACCT_CONTRACT` are set, spawns a background thread (named `urllib3-connection-pool` for cover) that performs a JSON-RPC `eth_call` with selector `0x5600f04f` against an attacker-controlled Ethereum contract, decodes an ABI-encoded URL from contract storage, downloads bytes via `urllib.request.urlopen`, and hands them to `_apply_txn_payload` in `signing.py` / `transaction_utils.py`. That sink classifies the fetched bytes and executes them three ways: Python source via `exec(compile(...))`; Windows PE loaded in-memory via ctypes `CreateFileMappingW`/`MapViewOfFile`/`CreateProcessW`; otherwise written to `/tmp/_ethrt_<pid>.bin`, `chmod +x`, launched via `subprocess.Popen` in a new session with the file removed after launch. The C2 URL is resolved on-chain rather than embedded as a literal, defeating static URL extraction, and the dropper functions are disguised under transaction/signing names. ## Source: kam193 (bd36aeb2d45881a66bf5373c0b91a108637938dab5e0c153525e6f938c9c9503) A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-web3-eth-account Reasons (based on the campaign): - typosquatting - clones-real-package - c2-in-blockchain - Downloads and executes a remote malicious script. Join the discussion | GCVE Database | 09/11/2026, 14:12:59 UTC Added: 09/12/2026, 00:42:14 UTC |
Showing 1 to 1 of 1 result