Logo
pypi

bitcoinlib-dev@0.4.21

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC

Malicious

OSV ID

MAL-2025-3436

Ecosystem

pypi

Summary

It overwrites the 'clw' command from legit bitconinlib package and attempts to exfiltrate its database on the usage. As a context, it appears to be created to lure users seeking for help with the bitconinlib package: https://github.com/1200wd/bitcoinlib/issues/455#issuecomment-2764513104 --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-bitcoinlibdbfix Reasons (based on the campaign): - files-exfiltration - crypto-related - action-hidden-in-lib-usage - exfiltration-crypto

Source: kam193 (a198ee5e2df9c67dcbd24ed19a8fec5d462bbb3c0eb474cf00cd299e75074ef5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.