logo

BIPClip: Malicious PyPI packages target crypto wallet recovery passwords

ID: 4fce3dd4-dfa0-5f0c-97e0-dbbfb787509c

STIX ID: report--4fce3dd4-dfa0-5f0c-97e0-dbbfb787509c

Feed Name: ReversingLabs Blog

Threat Score
65/100

Date Published: 2024-03-12

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs describes the “BIPClip” supply-chain campaign in which multiple malicious PyPI packages (including bip39_mnemonic_decrypt, mnemonic_to_address, public-address-generator, erc20-scanner, hashdecrypts, and hashdecrypt) were used to steal BIP39 mnemonic phrases for crypto wallets by hiding exfiltration code in dependent packages and using obfuscation (Base64, misleading field names, name squatting). The report documents discovery timeline, shared C2 infrastructure, download counts (ranging from hundreds to ~4,295 for the oldest package), limited apparent impact due to quick takedowns, and provides IOCs and mitigations for developers to improve supply-chain hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.