VYPR

pypi · Malicious package advisory

Malware

cryptowallethash

MAL-2026-846

Malicious code in cryptowallethash (PyPI)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: kam193 (4d493d3c40b5136dd3ffea29264cf1066247cda3a10094201b4f71554ae3e592)
The package claims to calculate a hash value for usage in "cryptocurrency", but before returning the hash, it exfiltrates the plain value.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-02-old-cryptowallethash


Reasons (based on the campaign):


 - crypto-related


 - exfiltration-crypto

Compromised versions (3)

  • 0.0.6
  • 0.0.7
  • 0.0.8

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.