Logo
pypi

crypto-trader-py@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-16406

Ecosystem

pypi

Summary

The package presents itself as a crypto trading and backtesting toolkit, but ships no library code matching that description — SOURCES.txt lists only LICENSE, README, setup.py, and egg-info metadata, and top_level.txt is empty. setup.py unconditionally invokes _wus_boot() before setup() during pip install, which spawns a sibling script _cryptotr_b2ca69.py via subprocess.Popen using pythonw.exe with Windows creationflags 0x08000000 (CREATE_NO_WINDOW) to hide the console window, guarded by a tempdir lockfile (13f8811c38.lk) to avoid re-entry. Stealth markers (hidden-window flag, pythonw preference, silent try/except wrapping, obfuscated identifiers) and the absence of any advertised library content match a dropper cover-story pattern rather than a legitimate build step, and the child process runs on every install with no user interaction.

Source: amazon-inspector (33e855a3ce62e35b613e702e710b81900769c241707c80f6a61462df0927529c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.