{"id":"MAL-2026-10194","title":"Malicious code in solidity-dev (PyPI)","summary":"Malicious code in solidity-dev (PyPI)","severity":"none","vendor":"solidity-dev","product":"solidity-dev","ecosystem":"pip","affected":["solidity-dev"],"published":"2026-07-12","updated":"2026-07-12","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10194","references":[{"url":"https://www.virustotal.com/gui/file/4dd018d84f2f9c35caed7a2c684cff2c1ea3af3a113cceb078a0788eefb93f66/detection"},{"url":"https://bad-packages.kam193.eu/pypi/package/solidity-dev"},{"url":"https://pypi.org/project/solidity-dev/1.3.0/"}],"tags":["osv","pip"],"ingestedAt":"2026-07-12T18:57:28.119Z","slug":"MAL-2026-10194","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (30501f6602a5b5b436ef5d6224ec332fa866c9e8b9da4d0de3bc69de868b1fff)\nsolidity_dev/__init__.py contains a large base64-encoded Linux x86_64 ELF binary in _PAYLOAD_B64. On `import solidity_dev`, the module decodes the blob, writes it to disk with executable permissions via os/stat/shutil, and spawns it through subprocess. The dropped ELF references installer-owned wallet and key material paths (~/.ethereum/keystore, ~/.foundry/keystores, ~/.config/solana/id.json), browser wallet extensions (metamask, phantom, ledger), and BIP-39 / mnemonic / seed keyword scanning (including Spanish variants semilla, frase, clave, billetera), and uploads collected material to attacker-controlled destinations including api.pinata.cloud/pinning/pinFileToIPFS (with pinata_api_key / pinata_secret_api_key headers), ugu.se/upload, temp.sh, and transfer.sh. The binary also installs a cron entry (`0 */12 * * *`) via `crontab -l |... | crontab -`, giving the operator scheduled re-execution on the host. The package advertises 'Solidity development helpers' but ships no Solidity-related code — the name is a cover story for the dropper.\n\n## Source: kam193 (c9741120bba24fda94f8c03e68cb1f051626700a69f8558f4f032c15536ec271)\nThe package embeds an executable stealing cryptocurrency wallets data. During import, code saves the executable under a name suggesting system utility and configures cron to run it periodically. The exfiltrated data is encrypted using embedded RSA code before uploading to file-sharing services or IPFS.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-py-base58\n\n\nReasons (based on the campaign):\n\n\n - crypto-related\n\n\n - exfiltration-crypto\n\n\n - persistence\n\n\n## Affected packages\n\n- `solidity-dev`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}