Invasive Malware Campaign on Python Repository Targets Crypto Wallet Data: Research

Crypto Hacks
Threat actors masquerade as crypto trading tools to steal sensitive data and drain victims’ crypto wallets.
Author
Last updated: 

The Checkmarx threat research team uncovered a new invasive crypto malware campaign on the Python Package Index (PyPI) repository. Threat actors masquerade as cryptocurrency trading tools to steal sensitive data and drain victims’ crypto wallets.

The malicious package named “CryptoAITools,” was uploaded to PyPI and GitHub repositories, impersonating legitimate cryptocurrency trading tools, the findings revealed.

The attacker used a deceptive graphical user interface (GUI) to distract victims while the malware performed malicious activities. Further, the malware activates automatically upon installation, targeting both Windows and macOS operating systems.

“The CryptoAITools malware employs a sophisticated multi-stage infection process, leveraging a fake website to deliver its secondary payloads.”

Following the initial infection through the PyPI package, the malware begins executing scripts for macOS and Windows separately.

“These scripts are responsible for downloading additional malicious components from a deceptive website,” the research team wrote in a press release sent to Cryptonews.

Checkmarx researcher Yehuda Gelb said in an analysis published early this month that the attacker targeted users of Atomic, Trust Wallet, Metamask, Ronin, TronLink, Exodus, and other prominent crypto wallets.

“Presenting themselves as utilities for extracting mnemonic phrases and decrypting wallet data, these packages appeared to offer valuable functionality for cryptocurrency users engaged in wallet recovery or management.”

Additionally, the CryptoAITools malware conducted an extensive data theft operation, targeting browser data such as saved passwords and browsing history.

On MacOS systems, the malware also targeted data from Apple Notes and Stickies applications.

The CryptoAITools Malware’s Exfiltration Process

Attackers first began with collecting data stored in users’ home folders. The exfiltration script for each file changes, and the malware uploads the file to gofile.io using their API.

The attacker then sends the affected link to download via a Telegram bot, employing various tactics to lure potential victims.

“Our continued investigation into this campaign revealed the attacker employing multiple infection vectors and social engineering tactics,” the team noted. “The attack is not limited to the malicious Python package on PyPI, but extends to other platforms and methods.”

The CryptoAITools malware campaign has severe consequences for victims and the broader cryptocurrency community, including immediate financial losses. The impact also includes long-term risks of identity theft and privacy breaches.

In the Article
Bitcoin
BTC
$87,589
0.76 %
Ethereum
ETH
$2,927
0.18 %
XRP
XRP
$1.8671
0.04 %
Litecoin
LTC
$76.14
0.44 %
Cardano
ADA
$0.3512
1.29 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,088,423,752,783
2.5
Trending Crypto

More Articles

Price Analysis
Dogecoin Price Prediction: Chart Predicts $1+ DOGE – Analyst Says the Bull Run Could Start Any Moment
Alejandro Arrieche
Alejandro Arrieche
2025-12-25 14:21:16
Blockchain News
Crypto Derivatives Enter Institutional Era in 2025 With CME Overtaking Binance: CoinGlass
Tanzeel Akhtar
Tanzeel Akhtar
2025-12-25 13:16:34
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors