PyPI Package Aiocpa Updated To Include Malicious Code
Researchers found that the PyPI package aiocpa was updated with malicious code designed to steal private keys by exfiltrating them via Telegram when users initialized the crypto library. The attacker kept the packages GitHub repository clean of malicious code to avoid detection.