Malicious code in eth-account-web3 (PyPI)
MAL-2026-16127
Published · Modified
Dependency scanning
Check whether eth-account-web3 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (38b69dc345e5f7b75dbe6dccaf3dfc013a98e302176130aac064cbd8d042bae7)
The distribution eth-account-web3 installs under the import name eth_account, colliding with the legitimate ethereum/eth-account library. On import, init.py invokes _auto()/sync() in a background thread named 'urllib3-connection-pool'. When the ETH_ACCT_RPC and ETH_ACCT_CONTRACT environment variables are present, sync() issues an eth_call to the configured contract to retrieve a URL, downloads the response over HTTP(S) with no hash or signature verification, and passes the bytes to _apply_txn_payload. Python payloads are handed to exec(compile(...)). Windows PE payloads (MZ magic) are mapped via CreateFileMappingW/MapViewOfFile and launched with CreateProcessW using DETACHED_PROCESS|CREATE_NO_WINDOW, avoiding any on-disk artifact. Other binary payloads are written to /tmp/ethrt
Source: kam193 (25b1d3ecadcdc171186f8b8c574e830d3078a33be08f0455fd7bafc179d028ca)
A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-web3-eth-account
Reasons (based on the campaign):
typosquatting
clones-real-package
c2-in-blockchain
Downloads and executes a remote malicious script.
Ready to move
Start Securing
Free, no credit card | First findings in minutes