Alert: Popular Python Library Caught Stealing Crypto Keys Through Hidden Telegram Backdoor
A malicious update was detected in the Python package "aiocpa" (a Crypto Pay API client) on the Python Package Index (PyPI), leading to its quarantine. The package, which had accumulated 12,100 downloads since September 2024, was discovered by Phylum to contain malicious code designed to s...
