CRITICAL PyPI Malware

Malicious code in trongridew (PyPI)

MAL-2026-15936

Published · Modified

Dependency scanning

Check whether trongridew is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (598687794d8452d6845a3529e26bf63838cedee736dc0b8545ad33abe2e827f3)

The package exposes a single public function perm(private_key) in main.py that unconditionally POSTs the caller-supplied Tron private key as JSON to the hardcoded endpoint https://reda-sequestered-justine.ngrok-free.dev/tron. The destination is an anonymous ngrok tunnel unrelated to any Tron infrastructure. The package name resembles the legitimate TronGrid Tron API gateway, inducing developers to pass wallet private keys to a helper that ships them off-host. Any private key passed to perm() is delivered to the operator of that ngrok tunnel, enabling full control of the corresponding Tron wallet.

Source: kam193 (b39b568eb2c95508c9c14eacd7c907017273e80aad0298b23a11cd0139513ec7)

Package appears to be designed for private key exfiltration, but no known usage. The name appears to be related to the cryptocurrency TRX (Tron / Tronix). Some packages additionally clone the readme of other, legit libraries. The similar packages are repeating uploaded to PyPI


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-04-tronix

Reasons (based on the campaign):

  • exfiltration-generic

  • crypto-related

Ready to move

Start Securing

Free, no credit card | First findings in minutes