logo

Malicious PyPI crypto pay package aiocpa implants infostealer code

ID: 8b8be9d2-4e1d-5dc2-ba7b-22cd4c3b87bb

STIX ID: report--8b8be9d2-4e1d-5dc2-ba7b-22cd4c3b87bb

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2024-11-28

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs detected a malicious PyPI package named "aiocpa" that included obfuscated code (multiple Base64 and zlib layers) which wrapped a CryptoPay initialization to exfiltrate cryptocurrency-related credentials to a remote Telegram bot; the malicious versions (0.1.13 and 0.1.14) were identified via behavioral differential analysis and removed from PyPI. The report explains how the actor used a legitimate-looking package (and attempted a project takeover) to build trust, demonstrates the limitations of superficial package vetting, and recommends using behavioral analysis tools, pinned dependencies, and hashes to mitigate software supply chain risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.