MAL-2026-13683
Dashboard / Malicious Package / MAL-2026-13683
MAL-2026-13683
Summary: Malicious code in kotoraka (PyPI)
Details: Source: amazon-inspector (e0b7d2fa2d2e401d5ca6c2cc4bb07964a955afa5e532e3947fdcfd6395570dd6) On import, kotoraka decodes base64-obfuscated filesystem paths pointing at the user's Monero wallet directory (Windows: C:\Users\<user>\Documents\Monero; Linux: /home/<user>/Monero), terminates any running `feather` or `monero` processes to release file locks, archives the wallet directory into a zip, and uploads it to the Telegram Bot API (api.telegram.org sendDocument) using a hardcoded bot token and chat_id (-5357046713). The Telegram bot token and target paths are stored as base64 literals decoded at runtime. The declared purpose of the package (an HTTP speed-up library) is unrelated to the actual behavior. The exfiltration fires as a top-level side effect of `import kotoraka`, with no user interaction. Source: kam193 (e9ba78f7ee9a259fc6e518295fe3d0217c83808bbdf0fff2107883cb3cf50b3c) During import, the package exfiltrates cryptocurrency wallet files. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-kotanku Reasons (based on the campaign): - exfiltration-crypto - uses-telegram-bot
References: https://bad-packages.kam193.eu/pypi/package/kotoraka, https://pypi.org/project/kotoraka/0.1.0/
Affected packages
Package
Name: kotoraka
Purl: pkg:pypi/kotoraka
Affected ranges
Type: N/A
Events:
