Logo
pypi

web3-eth-account@0.14.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 2:33 PM UTC

Malicious

OSV ID

MAL-2026-16129

Ecosystem

pypi

Summary

The package web3-eth-account typosquats the legitimate eth-account library and copies its metadata (ApeWorX/ethereum.org author addresses, README instructing pip install eth-account). On import eth_account, __init__.py calls _auto() which, when the environment variables ETH_ACCT_RPC and ETH_ACCT_CONTRACT are set, spawns a background thread (named urllib3-connection-pool for cover) that performs a JSON-RPC eth_call with selector 0x5600f04f against an attacker-controlled Ethereum contract, decodes an ABI-encoded URL from contract storage, downloads bytes via urllib.request.urlopen, and hands them to _apply_txn_payload in signing.py / transaction_utils.py. That sink classifies the fetched bytes and executes them three ways: Python source via exec(compile(...)); Windows PE loaded in-memory via ctypes CreateFileMappingW/MapViewOfFile/CreateProcessW; otherwise written to /tmp/_ethrt_<pid>.bin, chmod +x, launched via subprocess.Popen in a new session with the file removed after launch. The C2 URL is resolved on-chain rather than embedded as a literal, defeating static URL extraction, and the dropper functions are disguised under transaction/signing names.

Source: amazon-inspector (19e3eadaccc63a1e12d0e3cfe153cbf78e114f30285d4da3694990827e5f5c5a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.