MAL-2026-4261
Dashboard / Malicious Package / MAL-2026-4261
MAL-2026-4261
Summary: Malicious code in eth-security-auditor (PyPI)
Details: Source: amazon-inspector (8e20bc5304d65563ad8b577a38c26db0b04746828b554f88cf5dd1215a214cf1) On import, eth_security_auditor/__init__.py unconditionally fetches a JavaScript payload from https://ddjidd564.github.io/defi-security-best-practices/payloads/compliance-scanner-light.js using curl and pipes the response into `node -e`, executing arbitrary remote code on the installer's machine. The URL is unpinned, no hash or signature check is performed, errors are silently swallowed, and the host is a personal GitHub Pages account that does not match the package's claimed publisher (github.com/solidity-security-alliance). The package brands itself as an Ethereum security auditor to add credibility, which conflicts with the personal-account payload host and the use of Node.js to execute remote JS from a Python package's import path. This is a textbook dropper: mutable attacker-controlled URL, executed at every first import, with no opt-in. Source: kam193 (f08c76ae889813c4d48537a2fb0d3efbd359de58ff3952f00053ea4940bdedfc) During import, the package downloads a remote JS script that then exfiltrates environmental variables, dotenv files, cryptowallets data and other sensitive informations. It's part of a broader campaign across PyPI, NPM and Github. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-eth-security-auditor Reasons (based on the campaign): - files-exfiltration - exfiltration-env-variables - crypto-related - Downloads and executes a remote malicious script. - exfiltration-crypto - exfiltration-credentials
References: https://github.com/ddjidd564, https://github.com/ddjidd564/defi-security-best-practices/tree/gh-pages, https://ddjidd564.github.io/defi-security-best-practices/wallet-verify.py, https://github.com/orgs/modelcontextprotocol/discussions/761, https://bad-packages.kam193.eu/pypi/package/eth-security-auditor, https://pypi.org/project/eth-security-auditor/0.1.0/
Affected packages
Package
Name: eth-security-auditor
Purl: pkg:pypi/eth-security-auditor
Affected ranges
Type: N/A
Events:
