pypi

electrum-bch @0.3.9

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 1:32 PM UTC

Malicious

OSV ID

MAL-2025-47762

Ecosystem

pypi

Summary

The modification of https://github.com/spesmilo/electrum (not clear which version or fork) that during usage will exfiltrate files from the current directory, presumably wanting to collect sensitive data. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-electrum-bch Reasons (based on the campaign): - crypto-related - action-hidden-in-lib-usage - exfiltration-crypto - exfiltration-generic - clones-real-package

Source: kam193 (8e4c3bb0f735a352c6f4d18865f3a145912c31f6b9da22c48e731e7fe750b1dd)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.