logo

Malicious PyPI crypto pay package aiocpa implants infostealer code

ID: 53f8f12d-3b9f-59fe-a2e2-bb895b31ec14

STIX ID: report--53f8f12d-3b9f-59fe-a2e2-bb895b31ec14

Feed Name: infostealers.com

Threat Score
70/100

Date Published: 2024-12-13

Date Updated: 2026-06-07

Author: InfoStealers

...
...

ReversingLabs detected a malicious PyPI package, "aiocpa", that contained obfuscated infostealer code designed to exfiltrate cryptocurrency-related tokens to a Telegram bot. The attackers published legitimate-looking client versions to build trust, then introduced malicious updates (versions 0.1.13 and 0.1.14) and attempted a package-name takeover; RL’s Spectra platform identified the behavior and PyPI quarantined/removed the package. Provided IOCs include package names, versions, and SHA1 hashes for the malicious releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.