MAL-2026-3388

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/crypto-bot-utils/MAL-2026-3388.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3388
Published
2026-05-08T09:02:06Z
Modified
2026-05-08T09:51:31Z
Summary
Malicious code in crypto-bot-utils (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: kam193 (3ece4ae851dba85751377f47097bd30525eafdcbf8cd08b57d2a06aa3a02b367)

The code automatically scans the filesystem looking for BIP-39 seed phrases and data indicating private keys, and exfiltrates them


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-05-solana-wallet-sdk

Reasons (based on the campaign):

  • files-exfiltration

  • crypto-related

  • exfiltration-crypto

Database specific
{
    "iocs": {
        "ips": [
            "46.225.21.180"
        ],
        "urls": [
            "http://46.225.21.180:3000/api/narrative-accounts"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "pypi/2026-05-solana-wallet-sdk/crypto-bot-utils",
            "import_time": "2026-05-08T09:38:39.063479239Z",
            "modified_time": "2026-05-08T09:02:06.99841Z",
            "sha256": "3ece4ae851dba85751377f47097bd30525eafdcbf8cd08b57d2a06aa3a02b367",
            "source": "kam193",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / crypto-bot-utils

Package

Name
crypto-bot-utils
View open source insights on deps.dev
Purl
pkg:pypi/crypto-bot-utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/crypto-bot-utils/MAL-2026-3388.json"