btcli-security
MAL-2026-162
PyPItyposquat1/8/2026
Description
Malicious code in btcli-security (PyPI)
Indicators of Compromise
SHA256 Hashes (1)
a4b868f818b1a81f5fccee1967f70c3ff9d75c218d14ec09882c576a9c2c213e
Domains (2)
bitensor.xyzcameradriver.pro
IP Addresses (1)
23.227.203.99
References (4)
https://dmpdump.github.io/posts/NorthKorea_Backdoor_Stealer/OSVhttps://www.virustotal.com/gui/file-analysis/NTk2Y2FiNTBmM2QxODI2NDRlZGM0OTA2OGVjYzUxOTk6MTc2NzYzMzkzMA==OSVhttps://www.virustotal.com/gui/file/d02d6a5da3cff57d78e260961526420c172a46f4a07d18a3865fecbf5dfebc1d/detectionOSVhttps://bad-packages.kam193.eu/pypi/package/btcli-securityOSV
Details
EcosystemPyPI
Attack Typetyposquat
Published1/8/2026
Quick Actions