Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'pypi'

View all threats tagged with 'pypi'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: pypi

Threats Tagged 'pypi'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in kotanku (PyPI)
0

The kotanku package on PyPI version 0.1.0 contains malicious code that exfiltrates cryptocurrency wallet files during import. This behavior is part of a campaign identified as 2026-08-kotanku, which uses a Telegram bot for exfiltration. No official patch or remediation guidance is provided. There is no evidence of active exploitation in the wild at this time.

Join the discussion
Malicious code in pytablute (PyPI)
0

The pytablute package version 1.0.3 on PyPI contains malicious code that executes upon import or use. This code downloads a secondary malicious script and runs a background process that periodically connects to a remote host to receive and execute further commands. The package is obfuscated and designed to execute remote commands on the victim's machine, indicating clear malicious intent.

Join the discussion
Malicious code in chaintest (PyPI)
0

The chaintest package on PyPI version 0.1.0 contains malicious code functioning as a cryptocurrency infostealer. It exfiltrates sensitive data from browsers, including cryptowallet extensions and local storage, as well as standalone applications like password managers and cryptowallets. The malware achieves persistence on different platforms, runs a keylogger that alters copied cryptocurrency addresses to attacker-controlled ones, and can execute remote commands from a command-and-control server. It also exfiltrates SSH keys, installs malicious browser extensions, and shares similarities with a known DPRK-linked campaign.

Join the discussion
Malicious code in btcflip (PyPI)
0

The PyPI package 'btcflip' version 0.1.0 is a malicious library that, upon import, archives the user's Monero cryptocurrency wallet directory and exfiltrates it to a hardcoded Telegram bot. The package disguises itself as an HTTP speed-up library but contains code that terminates Monero-related processes to release file locks before stealing wallet files. The exfiltration target and wallet paths are obfuscated using base64 encoding. This behavior occurs immediately when the package is imported, making any use of the package a direct compromise of Monero wallet security.

Join the discussion
Malicious code in btcflx (PyPI)
0

The PyPI package 'btcflx' version 0.1.0 is a malicious library that, upon import, searches for Monero cryptocurrency wallet directories on the user's system, terminates related processes to unlock files, archives the wallet data, and exfiltrates it to a hardcoded Telegram bot. The package disguises itself as an HTTP speed-up library, misleading users about its true intent. It also sends status messages about the wallet discovery to the same Telegram bot. This behavior constitutes clear malicious activity aimed at stealing cryptocurrency wallet data.

Join the discussion
Malicious code in cubesat-upstream-driver (PyPI)
0

The PyPI package 'cubesat-upstream-driver' version 1.0.1 is a malicious package that masquerades as an upstream driver interface for cubesat orbital command bus but contains no actual driver or telemetry code. Instead, it defines a function that reads sensitive files and environment variables potentially containing secrets or flags, caching and exposing them via its public API. The package does not exfiltrate data by itself but appears designed to harvest secrets for external retrieval. It is likely used in a pentest or CTF-like scenario with low direct harm but poses a risk of secret leakage if integrated into a project.

Join the discussion
Malicious code in kotoraka (PyPI)
0

The kotoraka package on PyPI is a malicious package that, upon import, exfiltrates cryptocurrency wallet files from the user's system. It targets Monero wallet directories, terminates related processes to release file locks, archives the wallet data, and uploads it to a Telegram bot using hardcoded credentials. The package falsely declares itself as an HTTP speed-up library, but its actual behavior is data theft triggered immediately on import without user interaction.

Join the discussion
Malicious code in riakcs (PyPI)
0

The PyPI package 'riakcs' versions 0.0.1 and 0.5.0 contains malicious code that exfiltrates basic host information such as IP address and username upon installation or import. The package overrides the install command in setup.py to execute this malicious behavior. The package has no legitimate purpose beyond this data exfiltration.

Join the discussion
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
0

GitPython versions up to 3.1.57 contain a vulnerability in the IndexFile.from_tree, reset, and merge_tree methods where unguarded forwarding of git read-tree options allows an attacker to overwrite arbitrary files. The flaw arises because these methods append caller-controlled treeish strings to git read-tree commands without proper unsafe option checks or separators, enabling injection of the --index-output option to specify arbitrary file paths. This leads to arbitrary file overwrite with a valid git-index blob, potentially destroying or corrupting files accessible by the host process.

Join the discussion
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
0

GitPython versions up to 3.1.57 have a vulnerability in the Repo.init() method where unsafe git options are forwarded without validation. Specifically, the --template option can be exploited by an attacker to plant malicious git hooks that execute arbitrary code during subsequent git operations. This occurs because Repo.init() directly passes kwargs to git init without checking for unsafe options, unlike the clone path which has protections. Exploitation requires the attacker to control the template directory and stage executable hooks. A fix is available that adds unsafe option checks to Repo.init().

Join the discussion

Showing 1 to 10 of 170 results

Filters:Tag: pypi
Page 1 of 17
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses