pypi

btcflx @0.1.0

Vulnerability report · Last retrieved from osv.dev August 10, 2026 at 10:20 PM UTC

Malicious

OSV ID

MAL-2026-13682

Ecosystem

pypi

Summary

Package advertises itself as an HTTP speed-up library but on import of the top-level module unconditionally locates the user's Monero wallet directory (Windows C:\Users\<user>\Documents\Monero, Linux /home/<user>/Monero), kills running 'feather' and 'monero' processes to release file locks, archives the directory, and uploads it via api.telegram.org sendDocument to a hardcoded Telegram bot with chat_id -5044692933. A companion sendMessage call reports host reconnaissance status ('Found wallet... sending' / 'Did not find wallets') to the same chat. The Telegram bot token and both Monero directory paths are base64-encoded in source to hide the destination and targets. Package name and description do not mention cryptocurrency wallets, establishing a cover-story mismatch.

Source: amazon-inspector (839c411e8d33badaebd5e59b2d966dc000e631843a49ce9352caafd1b7dd9e12)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.