📦 Malicious PyPI Packages Target the bitcoinlib Library
On 3 April 2025, ReversingLabs disclosed bitcoinlibdbfix and bitcoinlib-dev — PyPI packages posing as fixes for bitcoinlib: they "overwrit[e] the legitimate clw cli command with malicious code that attempts to exfiltrate sensitive database files" (bitcoinlib's local wallet.db, which can hold keys). The authors joined GitHub discussions promoting their "fixes"; both packages were caught and pulled.
