bitcoinlib-dev@0.4.21
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC
OSV ID
MAL-2025-3436
Ecosystem
pypi
Summary
It overwrites the 'clw' command from legit bitconinlib package and attempts to exfiltrate its database on the usage. As a context, it appears to be created to lure users seeking for help with the bitconinlib package: https://github.com/1200wd/bitcoinlib/issues/455#issuecomment-2764513104 --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-bitcoinlibdbfix Reasons (based on the campaign): - files-exfiltration - crypto-related - action-hidden-in-lib-usage - exfiltration-crypto
Source: kam193 (a198ee5e2df9c67dcbd24ed19a8fec5d462bbb3c0eb474cf00cd299e75074ef5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.