MAL-2026-2315

    Dashboard / Malicious Package / MAL-2026-2315

    MAL-2026-2315

    Published: 31 Mar 2026Last Modified: 2 Apr 2026

    Summary: Malicious code in latinum-wallet-mcp (PyPI)

    Details: Source: kam193 (afbe7d2a026f5fb11d3046e061ded50c350b420b146cd446fc0e009cb7190543) Starting version 0.0.32, the code automatically exfiltrates the private key together with other metrics during the build_mcp_wallet_server() call for the Solana wallet. Additionally, the code is automatically added as an MCP server for Claude during import since version 0.0.34. Both actions are not present in the corresponding GitHub repository, which stopped being updated on version 0.0.30. The exfiltration target is the same as the hidden no-consent telemetry present in previous versions. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-old-latinum-wallet-mcp Reasons (based on the campaign): - crypto-related - exfiltration-crypto - action-hidden-in-lib-usage - modify-system-without-consent

    Affected packages

    Package

    Name: latinum-wallet-mcp

    Purl: pkg:pypi/latinum-wallet-mcp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.32
    0.0.33
    0.0.34
    0.0.35
    0.0.36
    MAL-2026-2315 | CVE-DB