logo

Ethereum private key stealer on PyPI downloaded over 1,000 times

ID: 07a67398-0684-5703-ade7-6d1ba7bc43ac

STIX ID: report--07a67398-0684-5703-ade7-6d1ba7bc43ac

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-03-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious PyPI package called "set-utils" disguised as a utility library intercepted Ethereum wallet creation functions to capture private keys, encrypted them with an embedded RSA public key, and exfiltrated the stolen data by embedding it in transactions sent via the Polygon network; the package targeted Python blockchain developers and was removed from PyPI after being discovered, but users who installed it should uninstall immediately and assume any generated wallets are compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.