Tag: Malicious PyPI Package

Malicious PyPI Package Impersonates SymPy Deploys XMRig Miner on Linux Hosts
News

Malicious PyPI Package Impersonates SymPy Deploys XMRig Miner on Linux Hosts

It has been revealed that a new malicious package in the Python Package Index (PyPI) poses as a well-known symbolic mathematics library in order to infect Linux machines with malicious payloads, such as a bitcoin miner. The package, called sympy-dev, attempts to trick unsuspecting users into believing they are downloading a "development version" of the library by imitating SymPy and copying its project description exactly. Since its initial release on January 17, 2026, it has been downloaded more than 1,100 times. The download count probably indicates that some developers may have been impacted by the malicious effort, even though it is not a trustworthy indicator of the quantity of infections. As of this writing, the package is still accessible for download. On hacked systems, t...
This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions
News

This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions

Researchers studying cybersecurity have found a malicious Python package on the Python Package Index (PyPI) repository that can impersonate well-known libraries in order to steal a victim's Ethereum private keys. The package in question is called set-utils, and it has been downloaded 1,077 times thus far. The official registry no longer offers it for download. The package imitates popular libraries like python-utils (712M+ downloads) and utils (23.5M+ downloads), posing as a straightforward utility for Python sets, according to software supply chain security firm Socket. By tricking gullible developers into installing the tainted program read more about This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions. Get up to date on the latest cybersecur...