216.73.217.22

Malicious PyPi Package Detected Stealing Crypto Tokens

· Published 16/04/2025 14:51 · Modified 16/04/2025 18:21

Export JSON

Essential information

Published
16/04/2025 14:51
Modified
16/04/2025 18:21
Tags
2025-04-16 api-hijacking ccxt cryptocurrency mexc pypi supply chain attack
Related entities
2 observables, 4 techniques (mitre), 1 others

Description

A malicious package named --futures has been discovered by security researchers. This package claims to extend the capabilities of the legitimate library for trading, specifically for futures trading on the exchange. However, it actually hijacks user orders and steals crypto tokens. The package overrides certain API functions, redirecting trading requests to a malicious server at greentreeone.com instead of the legitimate platform. It uses obfuscation techniques to hide its malicious code and tricks users into believing their orders are being processed normally. The attackers can potentially steal API keys, secrets, and other sensitive information used for crypto trading. Users are advised to revoke any compromised tokens and remove the malicious package immediately.

External references