By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: PyPI Python Library “aiocpa” Found Exfiltrating Crypto Keys via Telegram Bot
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > PyPI Python Library “aiocpa” Found Exfiltrating Crypto Keys via Telegram Bot
Tech News

PyPI Python Library “aiocpa” Found Exfiltrating Crypto Keys via Telegram Bot

By Viral Trending Content 3 Min Read
Share
SHARE

Nov 25, 2024Ravie LakshmananSoftware Supply Chain / Malware

Crypto Keys via Telegram Bot

The administrators of the Python Package Index (PyPI) repository have quarantined the package “aiocpa” following a new update that included malicious code to exfiltrate private keys via Telegram.

The package in question is described as a synchronous and asynchronous Crypto Pay API client. The package, originally released in September 2024, has been downloaded 12,100 times to date.

By putting the Python library in quarantine, it prevents further installation by clients and cannot be modified by its maintainers.

Cybersecurity outfit Phylum, which shared details of the software supply chain attack last week, said the author of the package published the malicious update to PyPI, while keeping the library’s GitHub repository clean in an attempt to evade detection.

Cybersecurity

It’s currently not clear if the original developer was behind the rogue update or if their credentials were compromised by a different threat actor.

Signs of malicious activity were first spotted in version 0.1.13 of the library, which included a change to the Python script “sync.py” that’s designed to decode and run an obfuscated blob of code immediately after the package is installed.

Crypto Keys via Telegram Bot

“This particular blob is recursively encoded and compressed 50 times,” Phylum said, adding it’s used to capture and transmit the victim’s Crypto Pay API token using a Telegram bot.

It’s worth noting that Crypto Pay is advertised as a payment system based on Crypto Bot (@CryptoBot) that allows users to accept payments in crypto and transfer coins to users using the API.

The incident is significant, not least because it highlights the importance of scanning the package’s source code prior to downloading them, as opposed to just checking their associated repositories.

“As evidenced here, attackers can deliberately maintain clean source repos while distributing malicious packages to the ecosystems,” the company said, adding the attack “serves as a reminder that a package’s previous safety record doesn’t guarantee its continued security.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Cyber Security, Cybersecurity, Internet, Malware, Open Source, Phylum, PyPI, Python, Software Supply Chain, Telegram
Share This Article
Facebook Twitter Copy Link
Previous Article Dogecoin Whale Makes $84 Million Coinbase Deposit, Bearish Sign?
Next Article Farcaster founder teases Frames v2 ahead of full launch in 2025
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?