pypi · Malicious package advisory
Malwareeth-account-web3
GHSA-wg93-942j-x57j
Malicious code in eth-account-web3 (PyPI)
Details
**Severity:** Critical **Affected versions:** `= 0.14.0` ## Source: kam193 (25b1d3ecadcdc171186f8b8c574e830d3078a33be08f0455fd7bafc179d028ca) A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-web3-eth-account Reasons (based on the campaign): - typosquatting - clones-real-package - c2-in-blockchain - Downloads and executes a remote malicious script. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/76fca84d951bd7c535edfd649d3892a2c1e9911f/osv/malicious/pypi/eth-account-web3/MAL-2026-16127.json)) **References:** - https://bad-packages.kam193.eu/pypi/package/eth-account-web3 - https://github.com/ossf/malicious-packages/blob/76fca84d951bd7c535edfd649d3892a2c1e9911f/osv/malicious/pypi/eth-account-web3/MAL-2026-16127.json - https://github.com/advisories/GHSA-wg93-942j-x57j
Compromised versions (1)
- = 0.14.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.