MAL-2026-16129
Malicious code in web3-eth-account (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: kam193 (bd36aeb2d45881a66bf5373c0b91a108637938dab5e0c153525e6f938c9c9503) A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package.
---
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-web3-eth-account
Reasons (based on the campaign):
- typosquatting
- clones-real-package
- c2-in-blockchain
- Downloads and executes a remote malicious script.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for web3-eth-account (pip). Pin to a known-safe version or switch to an alternative.