CRITICAL PyPI Malware

Malicious code in web3-eth-account (PyPI)

MAL-2026-16129

Published · Modified

Dependency scanning

Check whether web3-eth-account is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (19e3eadaccc63a1e12d0e3cfe153cbf78e114f30285d4da3694990827e5f5c5a)

The package web3-eth-account typosquats the legitimate eth-account library and copies its metadata (ApeWorX/ethereum.org author addresses, README instructing pip install eth-account). On import eth_account, __init__.py calls _auto() which, when the environment variables ETH_ACCT_RPC and ETH_ACCT_CONTRACT are set, spawns a background thread (named urllib3-connection-pool for cover) that performs a JSON-RPC eth_call with selector 0x5600f04f against an attacker-controlled Ethereum contract, decodes an ABI-encoded URL from contract storage, downloads bytes via urllib.request.urlopen, and hands them to _apply_txn_payload in signing.py / transaction_utils.py. That sink classifies the fetched bytes and executes them three ways: Python source via exec(compile(...)); Windows PE loaded in-memory via ctypes CreateFileMappingW/MapViewOfFile/CreateProcessW; otherwise written to /tmp/_ethrt_<pid>.bin, chmod +x, launched via subprocess.Popen in a new session with the file removed after launch. The C2 URL is resolved on-chain rather than embedded as a literal, defeating static URL extraction, and the dropper functions are disguised under transaction/signing names.

Source: kam193 (bd36aeb2d45881a66bf5373c0b91a108637938dab5e0c153525e6f938c9c9503)

A clone of a legitimate package with import-time malicious code activating if specific env variables are set. Once activated, it queries the blockchain to retrieve the next stage URL stored in a smart contract. The payload from the URL is then downloaded and executed. The address of the smart contract is not included in the package.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-web3-eth-account

Reasons (based on the campaign):

  • typosquatting

  • clones-real-package

  • c2-in-blockchain

  • Downloads and executes a remote malicious script.

Ready to move

Start Securing

Free, no credit card | First findings in minutes