{"id":"MAL-2026-10194","summary":"Malicious code in solidity-dev (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (30501f6602a5b5b436ef5d6224ec332fa866c9e8b9da4d0de3bc69de868b1fff)\nsolidity_dev/__init__.py contains a large base64-encoded Linux x86_64 ELF binary in _PAYLOAD_B64. On `import solidity_dev`, the module decodes the blob, writes it to disk with executable permissions via os/stat/shutil, and spawns it through subprocess. The dropped ELF references installer-owned wallet and key material paths (~/.ethereum/keystore, ~/.foundry/keystores, ~/.config/solana/id.json), browser wallet extensions (metamask, phantom, ledger), and BIP-39 / mnemonic / seed keyword scanning (including Spanish variants semilla, frase, clave, billetera), and uploads collected material to attacker-controlled destinations including api.pinata.cloud/pinning/pinFileToIPFS (with pinata_api_key / pinata_secret_api_key headers), ugu.se/upload, temp.sh, and transfer.sh. The binary also installs a cron entry (`0 */12 * * *`) via `crontab -l |... | crontab -`, giving the operator scheduled re-execution on the host. The package advertises 'Solidity development helpers' but ships no Solidity-related code — the name is a cover story for the dropper.\n\n## Source: kam193 (c9741120bba24fda94f8c03e68cb1f051626700a69f8558f4f032c15536ec271)\nThe package embeds an executable stealing cryptocurrency wallets data. During import, code saves the executable under a name suggesting system utility and configures cron to run it periodically. The exfiltrated data is encrypted using embedded RSA code before uploading to file-sharing services or IPFS.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-py-base58\n\n\nReasons (based on the campaign):\n\n\n - crypto-related\n\n\n - exfiltration-crypto\n\n\n - persistence\n","modified":"2026-07-12T15:31:56.990330383Z","published":"2026-07-12T08:18:41Z","database_specific":{"malicious-packages-origins":[{"versions":["1.3.0"],"source":"kam193","sha256":"c9741120bba24fda94f8c03e68cb1f051626700a69f8558f4f032c15536ec271","import_time":"2026-07-12T09:13:05.574286065Z","id":"pypi/2026-07-py-base58/solidity-dev","modified_time":"2026-07-12T08:18:46.298221Z"},{"import_time":"2026-07-12T15:24:47.832616914Z","id":"IN-MAL-2026-009750","modified_time":"2026-07-12T15:11:22Z","versions":["1.3.0"],"source":"amazon-inspector","sha256":"30501f6602a5b5b436ef5d6224ec332fa866c9e8b9da4d0de3bc69de868b1fff"}]},"references":[{"type":"EVIDENCE","url":"https://www.virustotal.com/gui/file/4dd018d84f2f9c35caed7a2c684cff2c1ea3af3a113cceb078a0788eefb93f66/detection"},{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/solidity-dev"},{"type":"PACKAGE","url":"https://pypi.org/project/solidity-dev/1.3.0/"}],"affected":[{"package":{"name":"solidity-dev","ecosystem":"PyPI","purl":"pkg:pypi/solidity-dev"},"versions":["1.3.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"solidity_dev/__init__.py","sha256":"725c9770cafce248d5ed1cbb948b8e6bc3d0c3257258f29da2cce93396c9c220","tlsh":"fee48df7015bbdfa3a2c1d54a8412f501d7c664b152e8185f6c8ba7bb3e6250ce2ce39"}],"package_integrity":[{"filename":"solidity_dev-1.3.0-py3-none-any.whl","hashes":{"sha256":"c47709f9b22db36d5c9a8b94d712cbdfac60ac51e1d45603473ac971e2c5bcb3","blake2b_256":"a3231150b7755f31686e19420e6ebed777cfa2e54021178f6eb1002d74513f03","md5":"4d7836d9ff888fb1c2eb70a0c441ea93"}},{"hashes":{"blake2b_256":"6ff7c15e3f61c0c527415a91bc1144a2c9beb552b7c49a09b3bf7f8bf0a9b073","md5":"01bcaa6297e09e3a40dcc5108cfb4aee","sha256":"97d16ad2e76553a834ced579a069a0cc3a1977bb06852a2cd417ba60cc05d47f"},"filename":"solidity_dev-1.3.0.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/solidity-dev/MAL-2026-10194.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}