-= Per source details. Do not edit below this line.=-
Package silently exfiltrates the provided mnemonic
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-06-walletsutils
Reasons (based on the campaign):
crypto-related
action-hidden-in-lib-usage
exfiltration-crypto
{
"iocs": {
"urls": [
"http://89.23.98.149:5000/checkseed"
],
"ips": [
"89.23.98.149"
]
},
"malicious-packages-origins": [
{
"id": "RLMA-2025-03714",
"import_time": "2025-08-01T10:07:14.745155524Z",
"sha256": "52162033e9895851268d689c65748232f7e91ea06011658f0cdb8d2931ddfc63",
"source": "reversing-labs",
"modified_time": "2025-07-31T19:16:58Z",
"versions": [
"0.1.0"
]
},
{
"id": "pypi/2025-06-walletsutils/wallet-utils",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T22:30:55.723992235Z",
"sha256": "99f1fe9165a1bdc1a2c940119c87bd319d94e39dcb5a7ca8d15e229833b663a4",
"source": "kam193",
"modified_time": "2025-07-01T15:51:26Z"
},
{
"id": "pypi/2025-06-walletsutils/wallet-utils",
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-12-02T23:07:18.764132695Z",
"sha256": "c83a3acdf0b02acc2a9af7cf885f2f744a154847edc66e1264ee1c38d8d7b984",
"source": "kam193",
"modified_time": "2025-07-01T15:51:26Z"
},
{
"id": "pypi/2025-06-walletsutils/wallet-utils",
"import_time": "2025-12-10T21:38:57.933212104Z",
"sha256": "afa7c9d7f007f2a55f640b67f91902d30a140f1328fa4adaf4889c88bf96853d",
"source": "kam193",
"modified_time": "2025-07-01T15:51:26Z",
"versions": [
"0.1.0"
]
},
{
"id": "RLUA-2026-00902",
"import_time": "2026-03-19T12:20:41.90189079Z",
"sha256": "5b4cdc85005be739ebc9db213fe05a78b0c3b7f9e8b05eb05c5b7034c8298bb2",
"source": "reversing-labs",
"modified_time": "2026-03-18T12:20:20Z"
}
]
}