Logo
pypi

web3-eth-account@0.14.0

Vulnerability report · Last retrieved from osv.dev September 11, 2026 at 8:19 PM UTC

Malicious

OSV ID

MAL-2026-16129

Ecosystem

pypi

Summary

A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-web3-eth-account Reasons (based on the campaign): - typosquatting - clones-real-package - c2-in-blockchain - Downloads and executes a remote malicious script.

Source: kam193 (bd36aeb2d45881a66bf5373c0b91a108637938dab5e0c153525e6f938c9c9503)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.