New PyPI Malware ‘set-utils’ Exfiltrates Ethereum Private Ke...
Blog post from Socket
A malicious PyPI package named 'set-utils' was discovered by the Socket Research Team, designed to exfiltrate Ethereum private keys by exploiting common account creation functions and transmitting them via blockchain transactions through the Polygon RPC. Disguised as a utility for Python sets, it mimics popular libraries to deceive developers into installation, thereby granting unauthorized access to Ethereum wallets. Since its emergence in January 2025, it has been downloaded over 1,000 times, targeting Ethereum developers and organizations using Python-based blockchain applications. The malware silently hooks into standard wallet creation methods, transmits encrypted private keys via Polygon RPC, and modifies Ethereum account creation functions to ensure the theft of credentials. The attack poses significant financial risks by compromising any Ethereum wallets created while the package was active, highlighting the necessity for developers to employ proactive security measures like regular dependency audits and automated scanning tools to safeguard against such supply chain attacks. The malicious package has since been reported and removed from PyPI to prevent further compromise.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.