-= Per source details. Do not edit below this line.=-
Clone of a legitimate library with added malicious code that runs during generating a new mnemonic. The malicious code collects data related to cryptocurrency wallets and selected other files, and exfiltrate them to a hardcoded location.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-03-mnemoniclib
Reasons (based on the campaign):
clones-real-package
action-hidden-in-lib-usage
crypto-related
exfiltration-crypto
files-exfiltration
{
"iocs": {
"ips": [
"65.21.205.84"
],
"urls": [
"http://65.21.205.84:5000/upload"
]
},
"malicious-packages-origins": [
{
"id": "pypi/2026-03-mnemoniclib/mnemoniclib",
"import_time": "2026-03-30T12:50:52.341613423Z",
"modified_time": "2026-03-30T12:02:35.616053Z",
"sha256": "c88fa4e30e2437fef5f03db434adb0f34ee48d8bec2d3361d123b10086b28772",
"source": "kam193",
"versions": [
"0.20.1",
"0.21.1",
"0.22.1"
]
}
]
}