Crypto-Stealing Malware Discovered in Python Package Index, Targets Wallets

Researchers from Checkmarx uncovered malware on the Python Package Index (PyPI) that steals sensitive crypto wallet data, such as private keys and mnemonic phrases. Disguised as legitimate wallet tools, the malware has been downloaded over 3,700 times, affecting wallets like MetaMask and TronLink. Despite efforts to remove the threat earlier this year, the malicious code resurfaced in October.

DiscoveryCheckmarx cybersecurity firm identifies malware in Python Package Index (PyPI).
TargetMalware steals private keys, mnemonic phrases, and sensitive data from crypto wallets like MetaMask and TronLink.
MethodHidden within software packages mimicking legitimate wallet tools.
ImpactOver 3,700 downloads reported before detection.
ResponsePyPI previously suspended new projects in March 2024; malware resurfaced in October despite earlier actions.