VDB
Sign up

MAL-2026-16127

Malicious code in eth-account-web3 (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: kam193 (25b1d3ecadcdc171186f8b8c574e830d3078a33be08f0455fd7bafc179d028ca) A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package.

---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-web3-eth-account

Reasons (based on the campaign):

- typosquatting

- clones-real-package

- c2-in-blockchain

- Downloads and executes a remote malicious script.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/eth-account-web3

No fixed version published yet for eth-account-web3 (pip). Pin to a known-safe version or switch to an alternative.

References