The aiocpa PyPI Supply Chain Attack
Updated 5 Oct 2026 · Incident date 20 Nov 2024 · PyPI
aiocpa 0.1.12 -> 0.1.13 and 0.1.14cryptopay/utils/sync.pyThe PyPI package aiocpa shipped malicious versions 0.1.13 and 0.1.14 on 20 November 2024. The code sent the arguments of the Crypto Pay client to a Telegram bot that the attacker controlled.
PyPI quarantined the package and then removed it. This page lists the facts from the PyPI blog, the GitHub advisory and ReversingLabs.
What happened
The attackers built a real crypto client first and then added malware in a later release. The ReversingLabs analysis says they did not copy an existing package name. They published their own tool to gain users and then pushed a bad update.
The PyPI analysis gives this timeline:
- 20 Nov 2024, 18:04 UTC: version 0.1.13 is published.
- 20 Nov 2024, 18:50 UTC: version 0.1.14 is published.
- 21 Nov 2024, 16:18 UTC: a ReversingLabs researcher reports the package.
- 21 Nov 2024, 18:29 UTC: PyPI quarantines it.
- 25 Nov 2024: PyPI publishes its analysis.
The malicious code sits in cryptopay/utils/sync.py at about line 44. PyPI describes about 50 layers of obfuscation with byte encoding, compression and reversals. ReversingLabs describes recursive Base64 and zlib layers. When the code runs, it takes over the CryptoPay constructor. It sends the tokens and API server details passed to the client to the attacker's Telegram bot.
PyPI notes that the project's GitHub repository held clean code. The malware was only in the published packages. ReversingLabs reports more than 10,000 downloads before removal.
Affected versions
- Malicious: aiocpa 0.1.13 and 0.1.14.
- Clean per PyPI: 0.1.0 through 0.1.12.
- No patched release exists. All affected versions were removed from PyPI.
The advisory GHSA-486g-47cc-8wxf lists a severity of High (CVSS 8.3) and no CVE.
Indicators of compromise
- Package name
aiocpaat version 0.1.13 or 0.1.14. The internal module name iscryptopay. - Heavily obfuscated Base64 and zlib code in
cryptopay/utils/sync.py. - SHA1 of the 0.1.13 file listed by ReversingLabs:
a1187d2a4acfe8ddaee3c7be79a9bb838142903a - SHA1 of the 0.1.14 file listed by ReversingLabs:
01f7db47368bffa279fb15c688518774454650cf - Outbound requests to a Telegram bot API endpoint when your code creates the Crypto Pay client.
ReversingLabs lists the hashes as a partial list. The sources do not give the bot token or chat id.
How to check
Check whether aiocpa is installed and which version.
pip show aiocpa
Search every environment, lockfile and requirements file for the package.
grep -rniE "aiocpa==?0\.1\.1[34]" . --include="*.txt" --include="*.lock" --include="*.toml"
Do not import the package to test it. Importing runs the obfuscated code.
What to do now
- Uninstall aiocpa from every environment with
pip uninstall aiocpa. - Revoke and replace every Crypto Pay API token that you passed to the client.
- Review your Crypto Pay account for unexpected activity.
- Pin dependency versions with hash checking so that an unexpected release cannot install silently.
- Monitor outbound network traffic from build and production hosts.
Vigilance compares the version you trust with a new one. Here, sync.py gained multi-layer decode-and-execute code and an outbound send of client arguments. That is a new capability in a file that held plain library code in 0.1.12.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 10 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED cryptopay/utils/sync.py It now reads saved passwords and access keys and runs other programs. It did not before.
Frequently asked questions
Which aiocpa versions are malicious?
Versions 0.1.13 and 0.1.14, both published on 20 November 2024. PyPI lists versions 0.1.0 through 0.1.12 as clean.
What did the aiocpa malware steal?
It sent the arguments that a developer passes when creating the Crypto Pay client, such as API tokens and server details, to a Telegram bot that the attacker controlled.
Is aiocpa still on PyPI?
No. PyPI quarantined the package on 21 November 2024 and then removed it.
Sources
More supply chain attacks
- Microsoft durabletask PyPI compromise (TeamPCP) 19 May 2026
- LiteLLM PyPI backdoor (TeamPCP) 24 Mar 2026
- num2words hijack (PyPI phishing campaign / Scavenger malware) 28 Jul 2025
- Ultralytics PyPI compromise (GitHub Actions cache poisoning) 4 Dec 2024
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.