VYPR

pypi · Malicious package advisory

Malware

mnemoniclib

MAL-2026-2299

Malicious code in mnemoniclib (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (c88fa4e30e2437fef5f03db434adb0f34ee48d8bec2d3361d123b10086b28772)
Clone of a legitimate library with added malicious code that runs during generating a new mnemonic. The malicious code collects data related to cryptocurrency wallets and selected other files, and exfiltrate them to a hardcoded location.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-03-mnemoniclib


Reasons (based on the campaign):


 - clones-real-package


 - action-hidden-in-lib-usage


 - crypto-related


 - exfiltration-crypto


 - files-exfiltration

Compromised versions (3)

  • 0.20.1
  • 0.21.1
  • 0.22.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.