Heads up guys! If you're dealing with Python packages for Bitcoin or e-commerce, be cautious! There are two shady packages out there, bitcoinlibdbfix and bitcoinlib-dev, that claim to fix bugs in the real bitcoinlib, but they're actually trying to steal your info. Also, watch out for disgrasya, which has a nasty carding script for WooCommerce!
Warning: Malicious Python Packages Found
4 replies 59 views
Yeah, this stuff isn’t new. Using library distributions to spread malware has been a common tactic. But seriously, disgrasya has over 37,000 downloads? Google it, and you end up on some language site instead of anything programming-related. So sketchy.
Totally agree. And there's not much we can do to prevent this type of stuff. The good thing is that PyPI acted fast and removed disgrasya once it was flagged as malicious. But Google's bots aren't finding anything now, so that might help.
chain_diamondMember
Posts: 17 · Reputation: 52
#4Sep 25, 2025, 01:15 AM
True, but it just shows how weak PyPI's review processes really are against these supply chain attacks. We definitely need better mechanisms for software distribution to avoid these issues.
Yeah, all three of these packages are flagged and gone from PyPI now. When messing with crypto or finance-related stuff, a few precautions can save you a lot of trouble. Always check if the repo is open source, look for stars, forks, and issues, and see when it was last updated. Sites like library.io can help spot reliable packages.
Related topics
- Issues with ripemd160 on Ubuntu 22 9
- New Bitcoin Improvement Proposal with $100 Reward 9
- Clipboard Vulnerabilities in Cryptocurrency Transactions 8
- Understanding the Differences Between Traditional and Simplified Chinese Mnemonics 6
- Running Bitcoin Core on a Laptop with Limited Storage 20
- Exploring Blockstream's Satellite Tech and Its Potential 22