Ethereum private key stealer on PyPI downloaded over 1,000 times
ID: 07a67398-0684-5703-ade7-6d1ba7bc43ac
STIX ID: report--07a67398-0684-5703-ade7-6d1ba7bc43ac
Feed Name: Bleeping Computer
A malicious PyPI package called "set-utils" disguised as a utility library intercepted Ethereum wallet creation functions to capture private keys, encrypted them with an embedded RSA public key, and exfiltrated the stolen data by embedding it in transactions sent via the Polygon network; the package targeted Python blockchain developers and was removed from PyPI after being discovered, but users who installed it should uninstall immediately and assume any generated wallets are compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
