MAL-2026-13683

    Dashboard / Malicious Package / MAL-2026-13683

    MAL-2026-13683

    Published: 10 Aug 2026Last Modified: 10 Aug 2026

    Summary: Malicious code in kotoraka (PyPI)

    Details: Source: amazon-inspector (e0b7d2fa2d2e401d5ca6c2cc4bb07964a955afa5e532e3947fdcfd6395570dd6) On import, kotoraka decodes base64-obfuscated filesystem paths pointing at the user's Monero wallet directory (Windows: C:\Users\<user>\Documents\Monero; Linux: /home/<user>/Monero), terminates any running `feather` or `monero` processes to release file locks, archives the wallet directory into a zip, and uploads it to the Telegram Bot API (api.telegram.org sendDocument) using a hardcoded bot token and chat_id (-5357046713). The Telegram bot token and target paths are stored as base64 literals decoded at runtime. The declared purpose of the package (an HTTP speed-up library) is unrelated to the actual behavior. The exfiltration fires as a top-level side effect of `import kotoraka`, with no user interaction. Source: kam193 (e9ba78f7ee9a259fc6e518295fe3d0217c83808bbdf0fff2107883cb3cf50b3c) During import, the package exfiltrates cryptocurrency wallet files. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-kotanku Reasons (based on the campaign): - exfiltration-crypto - uses-telegram-bot

    Affected packages

    Package

    Name: kotoraka

    Purl: pkg:pypi/kotoraka

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.0
    MAL-2026-13683 | CVE-DB