Malicious code in btcflip (PyPI)
Malware
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 10, 2026
Description
Published to the GitHub Advisory Database
Aug 10, 2026
Reviewed
Aug 10, 2026
Last updated
Aug 10, 2026
Source: kam193 (2b305ae4851e877fcea4950e019342d31782bde7e3c49d11847e2ede65776f78)
During import, the package exfiltrates cryptocurrency wallet files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-kotanku
Reasons (based on the campaign):
exfiltration-crypto
uses-telegram-bot
Credit: OpenSSF (source)
References