Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The PyPI Python library “aiocpa” discovered the exfiltration of crypto keys via a Telegram bot
Global Security

The PyPI Python library “aiocpa” discovered the exfiltration of crypto keys via a Telegram bot

AdminBy AdminNovember 25, 2024No Comments2 Mins Read
Crypto Keys via Telegram Bot
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 25, 2024Ravi LakshmananSoftware Supply Chain / Malware

Crypto Keys via Telegram Bot

The administrators of the Python Package Index (PyPI) repository have quarantined the package “aiocpa” following a new update that included malicious code to steal private keys via Telegram.

The package in question described both synchronous and asynchronous Crypto Pay API the client. The pack, originally released in September 2024, has already been downloaded 12,100 times to date.

Placing a Python library in quarantine prevents it from being further installed by clients and cannot be modified by its maintainers.

Cyber ​​security company Phylum, which general details of the attack on the software supply chain last week, said the author of the package released a malicious update to PyPI while preserving the library GitHub repository clean in an attempt to avoid detection.

Cyber ​​security

It’s unclear at this point if the original developer was behind the fake update or if his credentials were compromised by another threat.

Signs of malicious activity were first seen in version 0.1.13 of the library, which included changes to the Python “sync.py” script, which is designed to decode and run a confusing block of code immediately after installing the package.

Crypto Keys via Telegram Bot

“This particular block is recursively encoded and compressed 50 times,” Fillum said, adding that it is used to capture and transfer the victim’s Crypto Pay API token using a Telegram bot.

It should be noted that Crypto Pay is advertised as a payment system based on Crypto bot (@CryptoBot) that allows users to accept payments in crypto and transfer coins to users using an API.

The incident is important not least because it highlights the importance of scanning a package’s source code before downloading them, rather than just checking its associated repositories.

“As demonstrated here, attackers can intentionally maintain clean source code repositories by spreading malicious packages across ecosystems,” the company said, adding that the attack “serves as a reminder that a package’s previous security record does not guarantee its continued security.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.