Malicious Python packages target popular Bitcoin library
ID: e408cfd8-8f4e-571f-bf5b-a46d1a23331c
STIX ID: report--e408cfd8-8f4e-571f-bf5b-a46d1a23331c
Feed Name: ReversingLabs Blog
Threat Score
ReversingLabs discovered two malicious PyPI packages (bitcoinlibdbfix and bitcoinlib-dev) masquerading as fixes for the popular bitcoinlib library; both attempted to replace the legitimate clw CLI with code designed to exfiltrate sensitive database files. The packages were flagged by ReversingLabs’ ML-driven Spectra platform and removed from PyPI, illustrating the growing use of ML to detect emerging software supply-chain threats targeting cryptocurrency tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
