This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions

Researchers studying cybersecurity have found a malicious Python package on the Python Package Index (PyPI) repository that can impersonate well-known libraries in order to steal a victim’s Ethereum private keys.

The package in question is called set-utils, and it has been downloaded 1,077 times thus far. The official registry no longer offers it for download.

The package imitates popular libraries like python-utils (712M+ downloads) and utils (23.5M+ downloads), posing as a straightforward utility for Python sets, according to software supply chain security firm Socket.

By tricking gullible developers into installing the tainted program read more about This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *