HomeSecurityCrypto wallets targeted via malicious Python packages

Crypto wallets targeted via malicious Python packages

Users of popular crypto wallets have been targeted by a supply chain attack involving Python packages that rely on malicious dependencies to steal sensitive information, Checkmarx warns

See also: Google Play: Fake WalletConnect app stole users' crypto

Crypto wallets Python

As part of the attack, several Python packages posing as legitimate tools for decrypting and managing data were uploaded to the PyPI on September 22, with the aim of helping users who want to recover and manage their crypto wallets.

The malicious packages targeted users of Atomic, Exodus, Metamask, Ronin, TronLink, Trust Wallet , and other popular crypto wallets.

To avoid detection, these packages listed multiple dependencies containing the malicious components and activated their malicious functions only when specific functions, rather than activating them immediately upon installation.

See also: USA: Sanctions on crypto exchange services Cryptex and PM2BTC for money laundering

Using names like AtomicDecoderss, TrustDecoderss , and ExodusDecodes, these packages aimed to attract developers and users of specific wallets and were accompanied by a professionally crafted README that included installation instructions and usage examples, as well as fake statistics.

Crypto wallets targeted via malicious Python packages
Crypto wallets targeted via malicious Python packages

In addition to the extraordinary level of detail to make the Python packages appear genuine, the attackers made them appear harmless upon first inspection by distributing functionality across dependencies and avoiding hardcoding the command and control (C&C) server into them.

The malicious code would only be activated when the user attempted to use one of the packages' advertised features. The malware would attempt to access the user's cryptocurrency wallet data and extract private keys, passphrases, along with other sensitive information and exfiltrate them.

With access to this sensitive information, attackers could empty victims' wallets and potentially set up the wallet for future asset theft.

See also: Marko Polo hackers target gamers/crypto users with info-stealer malware

Attacks on crypto wallets, such as those targeting Python packages, are a serious concern in the cryptocurrency world. Malicious attackers use a variety of methods to gain access to digital wallets, including phishing, malware, and brute force. It is critical for cryptocurrency holders to implement strong security measures, such as using hardware wallets, enabling two-factor authentication (2FA), and keeping their systems up to date with the latest software updates. With the increasing number of threats, awareness and prevention are becoming crucial to protecting digital assets.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS