logo

Malicious Python Packages Target Crypto Wallet Recovery Passwords

ID: 6858564a-d9a2-51ac-9404-f7af2485ea3c

STIX ID: report--6858564a-d9a2-51ac-9404-f7af2485ea3c

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2024-03-12

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

A newly discovered campaign called BIPClip distributes malicious Python packages on PyPI that steal BIP39 mnemonic seed phrases from developers. Malicious packages (including bip39_mnemonic_decrypt, mnemonic_to_address, public-address-generator, erc20-scanner, hashdecrypts/hashdecrypt) embed a decrypt_jsBIP39 function and related routines that decode a Base64 C2 URL and exfiltrate mnemonics via HTTP to attacker-controlled servers; code reuse and a linked older package suggest an ongoing supply-chain targeting of cryptocurrency projects, with measured but limited download counts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.