Malicious code in btcflx (PyPI)
Malware
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 10, 2026
Description
Published to the GitHub Advisory Database
Aug 10, 2026
Reviewed
Aug 10, 2026
Last updated
Aug 10, 2026
Source: kam193 (504aca220be0f03b6572f62dc3fc4a49ace09be61a969e39713c890f28afe62a)
During import, the package exfiltrates cryptocurrency wallet files.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-08-kotanku
Reasons (based on the campaign):
exfiltration-crypto
uses-telegram-bot
Credit: OpenSSF (source)
References