Watch out — these malicious PyPl packages could drain your wallet, and they’ve already been downloaded thousands of times


Be careful when downloading Python packages from PyPI – researchers have found some are malicious and looking to steal your cryptocurrency haul.
Cybersecurity researchers from ReversingLabs recently discovered seven such packages, whose goal is to steal BIP39 mnemonic phrases from its victims.
A cryptocurrency wallet is secured in two ways: with a password, and with a mnemonic phrase (a set of either 12 or 24 seemingly random words). When a user sets up a wallet, they generate a mnemonic phrase and a password. A password is used to log into the wallet, while the mnemonic phrase is used to restore the wallet, in case it needed to be installed on a different device or hardware wallet.
BIPClip has been in operation for over a year
By stealing the phrases, hackers would be able to load other people’s wallets onto their own devices, essentially getting unrestricted access to the funds.
Cumulatively, the packages were downloaded almost 7,500 times, before the researchers notified PyPI and the malware was removed. These are their names, so make sure you haven’t downloaded them:
jsBIP39-decrypt (126 downloads)
bip39-mnemonic-decrypt (689 downloads)
mnemonic_to_address (771 downloads)
erc20-scanner (343 downloads)
public-address-generator (1,005 downloads)
hashdecrypt (4,292 downloads)
hashdecrypts (225 downloads)
ReversingLabs dubbed the campaign BIPClip, and claim it kicked off in early December 2022.
“This is just the latest software supply chain campaign to target crypto assets,” security researcher Karlo Zanki said in a report shared with TheHackerNews. “It confirms that cryptocurrency continues to be one of the most popular targets for supply chain threat actors.”
PyPI, being one of the largest and most popular Python package repositories on the internet, is often the target of supply chain attacks. Hackers frequently impersonate legitimate packages, trying to trick developers into downloading malicious versions which exfiltrate their sensitive data and deploy malware and ransomware. At one point last year, PyPl was forced to suspend new projects and user sign-ups following a flood of malware.
More from TechRadar Pro
Be careful when downloading Python packages from PyPI – researchers have found some are malicious and looking to steal your cryptocurrency haul. Cybersecurity researchers from ReversingLabs recently discovered seven such packages, whose goal is to steal BIP39 mnemonic phrases from its victims. A cryptocurrency wallet is secured in two ways:…
Recent Posts
- Max Promo Code: 50% Off | February 2025
- Adidas Promo Codes & Deals: 30% Off
- Volvo’s ES90 sedan will be built with a Nvidia supercomputer
- With the Humane AI Pin now dead, what does the Rabbit R1 need to do to survive?
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010