MAL-2026-2405

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/eht-account/MAL-2026-2405.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-2405
Published
2026-04-01T17:49:00Z
Modified
2026-04-01T18:31:59.495552Z
Summary
Malicious code in eht-account (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (7e1fa4f35985059ad18e3e325fc65e1d25a5692cc9690a4b15af2d76492b95fe)

Clones of a legitimate library. During processing the private key, it's getting exfiltrated.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-04-ether-account

Reasons (based on the campaign):

  • clones-real-package

  • action-hidden-in-lib-usage

  • crypto-related

  • exfiltration-crypto

  • typosquatting

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "7e1fa4f35985059ad18e3e325fc65e1d25a5692cc9690a4b15af2d76492b95fe",
            "source": "kam193",
            "modified_time": "2026-04-01T17:49:00.342917Z",
            "id": "pypi/2026-04-ether-account/eht-account",
            "import_time": "2026-04-01T18:24:46.243233603Z",
            "versions": [
                "0.13.7"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / eht-account

Package

Affected ranges

Affected versions

0.*
0.13.7

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/eht-account/MAL-2026-2405.json"