The aiocpa PyPI Supply Chain Attack

Updated 5 Oct 2026 · Incident date 20 Nov 2024 · PyPI

Packageaiocpa 0.1.12 -> 0.1.13 and 0.1.14
Filecryptopay/utils/sync.py

aiocpa is a Python client for the Crypto Pay API. Versions 0.1.13 and 0.1.14 contained hidden code that sent the user's payment credentials to a Telegram bot. The attacker released both versions on 20 November 2024.

Versions 0.1.0 to 0.1.12 are safe. The malicious code was not in the public GitHub repository. It was only in the packages on PyPI.

What happened

The attacker published two poisoned releases of aiocpa to PyPI on 20 November 2024. The PyPI Security analysis says the project was created on 1 September 2024. Version 0.1.13 appeared at 18:04 UTC on 20 November. Version 0.1.14 followed at 18:50 UTC.

The malicious code was in cryptopay/utils/sync.py. It was wrapped in about 50 layers of obfuscation. These layers used byte encoding, compression, and reversal. When the library was imported, the code replaced the constructor of the CryptoPay class. It then sent the arguments, which include the API token, in an HTTP request to a Telegram bot.

ReversingLabs describes the layers as repeated Base64 encoding and zlib compression. ReversingLabs found the package on 21 November 2024 with machine learning threat hunting. It reported the package to PyPI. PyPI Security quarantined it that day at 18:29 UTC. PyPI published its analysis on 25 November 2024.

ReversingLabs reports more than 10,000 downloads before removal. The attackers did not copy the name of another package. They built a real crypto client first and attracted users. Then they poisoned later releases. ReversingLabs notes a takeover request for the project on 3 September 2024.

Affected versions

PyPI quarantined the project. No clean release exists after 0.1.12. Treat any install of 0.1.13 or 0.1.14 as exposed.

Indicators of compromise

How to check

Run pip show in each Python environment, including virtual environments and containers. The command does not run the package.

pip show aiocpa
pip freeze | grep -i aiocpa

If the version is 0.1.13 or 0.1.14, the code ran when your program imported the library. Search your lock files and image layers too.

grep -rn aiocpa requirements*.txt poetry.lock Pipfile.lock pyproject.toml

What to do now

  1. Remove aiocpa from every environment: pip uninstall aiocpa.
  2. Revoke and replace every Crypto Pay API token that an affected program used. PyPI Security tells users to audit credentials the Telegram bot could have received.
  3. Check your Crypto Pay account for payments you did not make.
  4. Pin dependency versions and use hash checking, for example pip install --require-hashes. PyPI and ReversingLabs both give this advice.
  5. Watch outbound network traffic from servers that hold payment keys.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old aiocpa-0.1.12 --new aiocpa-0.1.13
files scanned: 65

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    cryptopay/utils/sync.py
           It now downloads from the internet, reads saved passwords and access keys and runs other programs. It did not before.

Frequently asked questions

Which aiocpa versions are malicious?

Versions 0.1.13 and 0.1.14, both released on 20 November 2024. Versions 0.1.0 to 0.1.12 are reported safe.

What did the aiocpa malware steal?

It sent the arguments given to the CryptoPay class, which include the Crypto Pay API token, to a Telegram bot.

Was the aiocpa malware in the GitHub repository?

No. PyPI Security reports that the source repository showed no malware. The code was only in the packages on PyPI.

Sources

  1. blog.pypi.org/posts/2024-11-25-aiocpa-attack-analysis/
  2. reversinglabs.com/blog/malicious-pypi-crypto-pay-package-aiocpa-implants-infostealer-code

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free