bitcoinlibdbfix@0.4.14
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2025-3437
Ecosystem
pypi
Summary
It overwrites the 'clw' command from legit bitconinlib package and attempts to exfiltrate its database on the usage. As a context, it appears to be created to lure users seeking for help with the bitconinlib package: https://github.com/1200wd/bitcoinlib/issues/455#issuecomment-2764513104 --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-bitcoinlibdbfix Reasons (based on the campaign): - files-exfiltration - crypto-related - action-hidden-in-lib-usage - exfiltration-crypto
Source: kam193 (a5cb52fa4f2ac6a68416c59a513399e01bb388d5e238260b712a513db3d97233)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.