Malicious PyPI crypto pay package aiocpa implants infostealer code
ID: 8b8be9d2-4e1d-5dc2-ba7b-22cd4c3b87bb
STIX ID: report--8b8be9d2-4e1d-5dc2-ba7b-22cd4c3b87bb
Feed Name: ReversingLabs Blog
ReversingLabs detected a malicious PyPI package named "aiocpa" that included obfuscated code (multiple Base64 and zlib layers) which wrapped a CryptoPay initialization to exfiltrate cryptocurrency-related credentials to a remote Telegram bot; the malicious versions (0.1.13 and 0.1.14) were identified via behavioral differential analysis and removed from PyPI. The report explains how the actor used a legitimate-looking package (and attempted a project takeover) to build trust, demonstrates the limitations of superficial package vetting, and recommends using behavioral analysis tools, pinned dependencies, and hashes to mitigate software supply chain risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
