---
id: MAL-2026-13683
title: Malicious code in kotoraka (PyPI)
summary: Malicious code in kotoraka (PyPI)
severity: none
vendor: kotoraka
product: kotoraka
ecosystem: pip
affected:
  - kotoraka
published: '2026-08-10'
updated: '2026-08-10'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-13683'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/kotoraka'
  - url: 'https://pypi.org/project/kotoraka/0.1.0/'
tags:
  - osv
  - pip
ingestedAt: '2026-08-10T19:16:47.873Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e0b7d2fa2d2e401d5ca6c2cc4bb07964a955afa5e532e3947fdcfd6395570dd6)
On import, kotoraka decodes base64-obfuscated filesystem paths pointing at the user's Monero wallet directory (Windows: C:\Users\<user>\Documents\Monero; Linux: /home/<user>/Monero), terminates any running `feather` or `monero` processes to release file locks, archives the wallet directory into a zip, and uploads it to the Telegram Bot API (api.telegram.org sendDocument) using a hardcoded bot token and chat_id (-5357046713). The Telegram bot token and target paths are stored as base64 literals decoded at runtime. The declared purpose of the package (an HTTP speed-up library) is unrelated to the actual behavior. The exfiltration fires as a top-level side effect of `import kotoraka`, with no user interaction.

## Source: kam193 (e9ba78f7ee9a259fc6e518295fe3d0217c83808bbdf0fff2107883cb3cf50b3c)
During import, the package exfiltrates cryptocurrency wallet files.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-08-kotanku


Reasons (based on the campaign):


 - exfiltration-crypto


 - uses-telegram-bot


## Affected packages

- `kotoraka`

## Remediation

Refer to the advisory for the patched release.
