Malicious code in jupiter-sdk (PyPI)
-= Per source details. Do not edit below this line.=-
During import, the code downloads and executes a remote script. The script collects sensitive files, including cryptocurrency wallet private keys and seeds, SSH keys, dotenv files and uploads them to IPFS. After that, it communicates with C2 and awaits further commands to execute.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-metemask-sdk
Reasons (based on the campaign):
files-exfiltration
typosquatting
exfiltration-ssh-keys
crypto-related
Downloads and executes a remote malicious script.
exfiltration-crypto
The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
uses:ipfs
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준