Invasive Malware Campaign on Python Repository Targets Crypto Wallet Data: Research
Sujha has been recognised as 🟣 Women In Crypto 2024 🟣 by BeInCrypto for her leadership in crypto journalism.
- Bitcoin Triggers Sharp Flash Crash to $24K on Binance USD1 Pair
- Kyrgyz Som-Backed Stablecoin KGST is Now Live on Binance, President Confirms
- Spain to Implement Full EU MiCA Regulations Starting July 2026 – Report
- VanEck Manager Predicts Strong Bitcoin Comeback in 2026 Despite Its Current ‘Lag’
- Canadian Firm Matador Gets Ontario Regulator’s Nod to Raise $58M for More Bitcoin Buys

The Checkmarx threat research team uncovered a new invasive crypto malware campaign on the Python Package Index (PyPI) repository. Threat actors masquerade as cryptocurrency trading tools to steal sensitive data and drain victims’ crypto wallets.
The malicious package named “CryptoAITools,” was uploaded to PyPI and GitHub repositories, impersonating legitimate cryptocurrency trading tools, the findings revealed.
The attacker used a deceptive graphical user interface (GUI) to distract victims while the malware performed malicious activities. Further, the malware activates automatically upon installation, targeting both Windows and macOS operating systems.
“The CryptoAITools malware employs a sophisticated multi-stage infection process, leveraging a fake website to deliver its secondary payloads.”
Following the initial infection through the PyPI package, the malware begins executing scripts for macOS and Windows separately.
“These scripts are responsible for downloading additional malicious components from a deceptive website,” the research team wrote in a press release sent to Cryptonews.
Checkmarx researcher Yehuda Gelb said in an analysis published early this month that the attacker targeted users of Atomic, Trust Wallet, Metamask, Ronin, TronLink, Exodus, and other prominent crypto wallets.
“Presenting themselves as utilities for extracting mnemonic phrases and decrypting wallet data, these packages appeared to offer valuable functionality for cryptocurrency users engaged in wallet recovery or management.”
Additionally, the CryptoAITools malware conducted an extensive data theft operation, targeting browser data such as saved passwords and browsing history.
On MacOS systems, the malware also targeted data from Apple Notes and Stickies applications.
The CryptoAITools Malware’s Exfiltration Process
Attackers first began with collecting data stored in users’ home folders. The exfiltration script for each file changes, and the malware uploads the file to gofile.io using their API.
The attacker then sends the affected link to download via a Telegram bot, employing various tactics to lure potential victims.
“Our continued investigation into this campaign revealed the attacker employing multiple infection vectors and social engineering tactics,” the team noted. “The attack is not limited to the malicious Python package on PyPI, but extends to other platforms and methods.”
The CryptoAITools malware campaign has severe consequences for victims and the broader cryptocurrency community, including immediate financial losses. The impact also includes long-term risks of identity theft and privacy breaches.
- [LIVE] Fed Payments Innovation Conference: Real-Time Updates as Federal Reserve Discusses Crypto, Stablecoins, and AI with Industry Leaders
- Crypto Market Prospect: After the Washout, the Soil Looks Richer
- Bitcoin Price Prediction: BTC Price Drops Below $87,000, But Is a Christmas Reversal Possible?
- China’s DeepSeek AI Predicts the Price of XRP, BTC, and SOL By the End of 2025
- XRP Price Prediction: Franklin Templeton’s Spot ETF Tops 100M XRP in Holdings – Can Institutional Demand Push XRP Above $3?
About Us
2M+
250+
8
70
Market Overview
- 7d
- 1m
- 1y
- [LIVE] Fed Payments Innovation Conference: Real-Time Updates as Federal Reserve Discusses Crypto, Stablecoins, and AI with Industry Leaders
- Crypto Market Prospect: After the Washout, the Soil Looks Richer
- Bitcoin Price Prediction: BTC Price Drops Below $87,000, But Is a Christmas Reversal Possible?
- China’s DeepSeek AI Predicts the Price of XRP, BTC, and SOL By the End of 2025
- XRP Price Prediction: Franklin Templeton’s Spot ETF Tops 100M XRP in Holdings – Can Institutional Demand Push XRP Above $3?
More Articles
Get dialed in every Tuesday & Friday with quick updates on the world of crypto