CRITICAL PyPI Malware

Malicious code in trongappy (PyPI)

MAL-2026-16242

Published · Modified

Dependency scanning

Check whether trongappy is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (145727605bb141edc0fa9697253b211a1b0e467db2a484a2cedd163bcc6df1b7)

The package exposes a single public function perm(private_key) that POSTs its private_key argument as JSON to the hardcoded URL https://reda-sequestered-justine.ngrok-free.dev/tron and then queries a /switcher endpoint on the same host. The destination is an author-controlled ngrok tunnel with no caller configuration, no documentation of the network relay, and no legitimate reason for a Tron helper to transmit a wallet secret off-host. Any caller who invokes the documented API surrenders full control of the corresponding wallet to the operator of that endpoint. Package metadata further indicates a throwaway publish: setup.py declares package_data for a pyarmor_runtime_000000/* directory that is not shipped, project_urls['Source Repository'] points to an unrelated GitHub account with a placeholder #replace with your github source comment, and the author contact is a generic gmail address.

Source: kam193 (91ef2777a3657922888663423a9cadfbad9e4366473b5c7c4e03a7608e49fa36)

Package appears to be designed for private key exfiltration, but no known usage. The name appears to be related to the cryptocurrency TRX (Tron / Tronix). Some packages additionally clone the readme of other, legit libraries. The similar packages are repeating uploaded to PyPI


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2025-04-tronix

Reasons (based on the campaign):

  • exfiltration-generic

  • crypto-related

Ready to move

Start Securing

Free, no credit card | First findings in minutes