Hacking

New Malicious PyPI Packages Steal Crypto Wallet Data and Private Keys

Published  ·  4 min read

A new wave of malicious packages has been discovered in the Python Package Index (PyPI) repository, disguised as cryptocurrency wallet recovery and management tools. Instead of offering helpful services, these packages steal sensitive information and facilitate the theft of valuable digital assets.

"The attack targeted users of Atomic, Trust Wallet, Metamask, Ronin, TronLink, Exodus, and other prominent wallets in the crypto ecosystem," said Yehuda Gelb, a researcher at Checkmarx, in an analysis published on Tuesday.

Masquerading as utilities designed for extracting mnemonic phrases and decrypting wallet data, the packages seemed to provide useful functionality for cryptocurrency users looking to recover or manage their wallets. However, these tools harbored hidden functionality that allowed them to steal private keys, mnemonic phrases, and other sensitive data, such as transaction histories and wallet balances. Shockingly, each package attracted hundreds of downloads before they were eventually removed:

  • atomicdecoderss (366 downloads)
  • trondecoderss (240 downloads)
  • phantomdecoderss (449 downloads)
  • trustdecoderss (466 downloads)
  • exodusdecoderss (422 downloads)
  • walletdecoderss (232 downloads)
  • ccl-localstoragerss (335 downloads)
  • exodushcates (415 downloads)
  • cipherbcryptors (450 downloads)
  • ccl_leveldbases (407 downloads)

Checkmarx indicated that the names of these packages were deliberately chosen to entice developers working within the cryptocurrency ecosystem. To lend legitimacy, the PyPI package descriptions even included installation instructions, usage examples, and in one case, "best practices" for using virtual environments.

Fake Crypto Wallet Recovery Tools

The deception didn't stop at just misleading names. The attackers behind this campaign also manipulated download statistics, giving the packages an appearance of popularity and trustworthiness. Six of the identified packages included a dependency named cipherbcryptors, which executed the malicious actions, while others used an additional package called ccl_leveldbases, likely in an attempt to obscure the malicious functionality.

Notably, the packages’ harmful functionality wasn’t triggered automatically upon installation. Instead, it was only activated when specific functions were called, making it harder to detect compared to typical malware. Once triggered, the stolen data was exfiltrated to a remote server.

"The attacker added an extra layer of security by not hard-coding their command and control server address in any of the packages," Gelb explained. "Instead, they used external resources to dynamically retrieve the server information." This method, known as dead drop resolver, allows attackers to update the server address without needing to release a new package version. It also makes switching infrastructure easy if the original servers are taken down.

"The attack takes advantage of the trust in open-source communities and the perceived utility of wallet management tools, potentially affecting a wide range of cryptocurrency users," Gelb continued. "The complexity of this attack — from its deceptive packaging to dynamic malicious capabilities and use of dependencies — highlights the importance of comprehensive security measures and continuous monitoring."

This incident is the latest in a string of malicious campaigns targeting the cryptocurrency industry, as threat actors continue to seek new ways to drain funds from victim wallets.

PyPI Repository Attack

In August 2024, a sophisticated cryptocurrency scam known as CryptoCore was uncovered. This operation uses fake videos or hijacked accounts on platforms like Facebook, Twitch, X, and YouTube to trick users into handing over their cryptocurrency under the promise of quick profits.

"This scam group and its giveaway campaigns utilize deepfake technology, hijacked YouTube accounts, and professional-looking websites to lure users into sending their cryptocurrency to the scammers' wallets," said Avast researcher Martin Chlumecký.

"The most common tactic is convincing potential victims that messages or events posted online are official communications from a trusted social media account or event, piggybacking on the trust associated with the chosen brand, person, or event."

Just last week, another attack was highlighted by Check Point: a rogue Android app impersonating the legitimate WalletConnect open-source protocol. This app was responsible for stealing approximately $70,000 in cryptocurrency by initiating fraudulent transactions from infected devices.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067