MAL-2025-47762

    Dashboard / Malicious Package / MAL-2025-47762

    MAL-2025-47762

    Published: 23 Aug 2025Last Modified: 19 Mar 2026

    Summary: Malicious code in electrum-bch (PyPI)

    Details: Source: kam193 (8e4c3bb0f735a352c6f4d18865f3a145912c31f6b9da22c48e731e7fe750b1dd) The modification of https://github.com/spesmilo/electrum (not clear which version or fork) that during usage will exfiltrate files from the current directory, presumably wanting to collect sensitive data. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-electrum-bch Reasons (based on the campaign): - crypto-related - action-hidden-in-lib-usage - exfiltration-crypto - exfiltration-generic - clones-real-package

    Affected packages

    Package

    Name: electrum-bch

    Purl: pkg:pypi/electrum-bch

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.3.6
    0.3.7
    0.3.8
    0.3.9
    0.3.5