{"id":"MAL-2026-10195","title":"Malicious code in eth-agent (PyPI)","summary":"Malicious code in eth-agent (PyPI)","severity":"none","vendor":"eth-agent","product":"eth-agent","ecosystem":"pip","affected":["eth-agent"],"published":"2026-07-12","updated":"2026-07-12","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-10195","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/eth-agent"}],"tags":["osv","pip"],"ingestedAt":"2026-07-12T18:57:28.136Z","slug":"MAL-2026-10195","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (0268950ea20e5566a61026409820d6a1d4ac4d462f475ae4589c72390042fec6)\nDuring import, the code downloads and executes a remote script. The script collects sensitive files, including cryptocurrency wallet private keys and seeds, SSH keys, dotenv files and uploads them to IPFS. After that, it communicates with C2 and awaits further commands to execute.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-07-metemask-sdk\n\n\nReasons (based on the campaign):\n\n\n - files-exfiltration\n\n\n - typosquatting\n\n\n - exfiltration-ssh-keys\n\n\n - crypto-related\n\n\n - Downloads and executes a remote malicious script.\n\n\n - exfiltration-crypto\n\n\n - The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.\n\n\n - uses:ipfs\n\n\n## Affected packages\n\n- `eth-agent`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}