-= Per source details. Do not edit below this line.=-
During installation, the package exfiltrates sensitive env variables, browser data, crypto wallets files, ssh keys and other configuration files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-bip39-py
Reasons (based on the campaign):
crypto-related
The package overrides the install command in setup.py to execute malicious code during installation.
exfiltration-crypto
exfiltration-browser-data
exfiltration-env-variables
exfiltration-ssh-keys
exfiltration-credentials
uses-telegram-bot
{
"iocs": {
"domains": [
"40f955f39128bd79-178-249-214-24.serveousercontent.com"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-08-05T18:07:53.703177802Z",
"modified_time": "2026-08-05T17:47:51.237148Z",
"sha256": "b292686db581afeaaa7d53e2281a90d7d470fc71ab9e7d6156c49e2e99a44a30",
"id": "pypi/2026-08-bip39-py/defi-sdk-py",
"versions": [
"2.5.1"
],
"source": "kam193"
},
{
"source": "kam193",
"modified_time": "2026-08-05T17:47:51.237148Z",
"sha256": "1781d7fc50d63adba26cfa279d7ea0fc4c5e7658e8a2bcfbb5faa117825ab2a7",
"id": "pypi/2026-08-bip39-py/defi-sdk-py",
"versions": [
"2.5.1"
],
"import_time": "2026-08-05T19:04:59.177693687Z"
}
]
}