Logo
pypi

pybitjs@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-14545

Ecosystem

pypi

Summary

The package's setuptools cmdclasses (BuildPy, Develop) invoke node pybitjs/js/main.js during pip install, and write a pybitjs.pth file containing import pybitjs._autorun; pybitjs._autorun.run_main_js_once() so the same Node.js payload is re-executed on every subsequent Python interpreter startup. The bundled pybitjs/js/main.js is heavily string-array obfuscated (obfuscator.io style _0x240a / _0x4963) and implements an EtherHiding-style C2: it queries Ethereum JSON-RPC endpoints (drpc.org, publicnode.com, blockscout, etherscan-like API) for transactions involving the hardcoded address 0xa322E5f3..., extracts an IPv4 from the transaction data, HTTP-fetches an XOR-encrypted blob from that IP, decrypts it, and passes the decrypted content to eval(...) and to spawn('node', ['-e', <payload>], {detached:true}).unref(). Because the C2 host is dereferenced from an on-chain transaction, the destination is attacker-mutable, and installing or launching Python with this package present causes arbitrary attacker-controlled code to be fetched and executed on the installer's host.

Source: amazon-inspector (611713d33cb9efee440b0a416812cbb2ceda3d43c0cdc73c1f8b353400209df5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.