Knowledge Centre
Home / News / Cyber Insurance News / Python Package Index Targeted in Crypto Wallet Theft Campaign

Python Package Index Targeted in Crypto Wallet Theft Campaign

Published on March 20, 2024. EST READ TIME: 2 minutes

US Seizes Ransomware Gang’s Websites

A recent discovery by threat hunters reveals a coordinated attack on the Python Package Index (PyPI), with seven malicious packages designed to pilfer BIP39 mnemonic phrases crucial for cryptocurrency wallet recovery. Codenamed BIPClip, the campaign, uncovered by ReversingLabs, amassed over 7,000 downloads before removal from the repository. The attack, active since December 2022, targets developers working on crypto-related projects, with packages masquerading as legitimate tools. Notably, one package, mnemonic_to_address, operated innocuously, embedding malicious functionality in its dependency, bip39-mnemonic-decrypt. Security experts caution that the campaign, meticulously orchestrated to mimic authentic operations, underscores the persistent threat to crypto assets from supply chain attacks. The perpetrators, identified by references to a GitHub profile named "HashSnake," demonstrate a sophisticated approach, utilizing platforms like Telegram and YouTube to promote their illicit activities. This incident highlights the growing risk posed by compromised open-source repositories, emphasizing the need for robust security measures to thwart malicious actors exploiting abandoned projects as conduits for large-scale supply chain attacks.

Awards & Recognition
Image

BFSI Leadership Awards 2022 - Product Innovator of the Year (Optima Secure)

ETBFSI Excellence Awards 2021

FICCI Insurance Industry
Awards September 2021

ICAI Awards 2015-16

SKOCH Order-of-Merit

Best Customer Experience
Award of the Year

ICAI Awards 2014-15

Image

CMS Outstanding Affiliate World-Class Service Award 2015

Image

iAAA rating

Image

ISO Certification

Image

Best Insurance Company in Private Sector - General 2014

View all awards