BIPClip: Malicious PyPI packages target crypto wallet recovery passwords
ID: 4fce3dd4-dfa0-5f0c-97e0-dbbfb787509c
STIX ID: report--4fce3dd4-dfa0-5f0c-97e0-dbbfb787509c
Feed Name: ReversingLabs Blog
ReversingLabs describes the “BIPClip” supply-chain campaign in which multiple malicious PyPI packages (including bip39_mnemonic_decrypt, mnemonic_to_address, public-address-generator, erc20-scanner, hashdecrypts, and hashdecrypt) were used to steal BIP39 mnemonic phrases for crypto wallets by hiding exfiltration code in dependent packages and using obfuscation (Base64, misleading field names, name squatting). The report documents discovery timeline, shared C2 infrastructure, download counts (ranging from hundreds to ~4,295 for the oldest package), limited apparent impact due to quick takedowns, and provides IOCs and mitigations for developers to improve supply-chain hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
