216.73.216.6

Malicious PyPI crypto pay package aiocpa implants infostealer code

· Published 29/11/2024 10:48 · Modified 29/11/2024 11:03

Export JSON

Essential information

Published
29/11/2024 10:48
Modified
29/11/2024 11:03
Tags
2024-11-29 cryptocurrency infostealer machine learning obfuscation pypi software supply chain threat hunting
Related entities
6 techniques (mitre)

Description

ReversingLabs detected a malicious package named 'aiocpa' on , engineered to compromise wallets. Unlike typical attacks, the actors published their own crypto client tool to attract users before compromising them through a malicious update. The package appeared legitimate, with multiple versions and good documentation. -based revealed suspicious obfuscated code in versions 0.1.13 and 0.1.14, designed to exfiltrate sensitive crypto trading information. The incident highlights the growing sophistication of open-source software threats and the need for advanced security tools in development processes.

External references