National Cyber Warfare Foundation (NCWF) Forums


PyPI Python Library "aiocpa" Found Exfiltrating Crypto Keys via Telegram Bot


0 user ratings
2024-11-25 15:01:32
milo
Developers
The administrators of the Python Package Index (PyPI) repository have quarantined the package "aiocpa" following a new update that included malicious code to exfiltrate private keys via Telegram.
The package in question is described as a synchronous and asynchronous Crypto Pay API client. The package, originally released in September 2024, has been downloaded 12,100 times to date.
By putting the



Source: TheHackerNews
Source Link: https://thehackernews.com/2024/11/pypi-python-library-aiocpa-found.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.