Source |
The Hacker News |
Identifiant |
8617608 |
Date de publication |
2024-11-25 19:24:00 (vue: 2024-11-25 15:08:04) |
Titre |
PyPI Python Library "aiocpa" Found Exfiltrating Crypto Keys via Telegram Bot |
Texte |
The administrators of the Python Package Index (PyPI) repository have quarantined the package "aiocpa" following a new update that included malicious code to exfiltrate private keys via Telegram.
The package in question is described as a synchronous and asynchronous Crypto Pay API client. The package, originally released in September 2024, has been downloaded 12,100 times to date.
By putting the
The administrators of the Python Package Index (PyPI) repository have quarantined the package "aiocpa" following a new update that included malicious code to exfiltrate private keys via Telegram.
The package in question is described as a synchronous and asynchronous Crypto Pay API client. The package, originally released in September 2024, has been downloaded 12,100 times to date.
By putting the |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
100 2024 administrators aiocpa api asynchronous been bot client code crypto date described downloaded exfiltrate exfiltrating following found has have included index keys library malicious new originally package pay private putting pypi python quarantined question released repository september synchronous telegram times update |
Tags |
|
Stories |
|
Move |
|