The aiocpa PyPI Supply Chain Attack

Updated 5 Oct 2026 · Incident date 20 Nov 2024 · PyPI

Packageaiocpa 0.1.12 -> 0.1.13 and 0.1.14
Filecryptopay/utils/sync.py

The PyPI package aiocpa shipped malicious versions 0.1.13 and 0.1.14 on 20 November 2024. The code sent the arguments of the Crypto Pay client to a Telegram bot that the attacker controlled.

PyPI quarantined the package and then removed it. This page lists the facts from the PyPI blog, the GitHub advisory and ReversingLabs.

What happened

The attackers built a real crypto client first and then added malware in a later release. The ReversingLabs analysis says they did not copy an existing package name. They published their own tool to gain users and then pushed a bad update.

The PyPI analysis gives this timeline:

The malicious code sits in cryptopay/utils/sync.py at about line 44. PyPI describes about 50 layers of obfuscation with byte encoding, compression and reversals. ReversingLabs describes recursive Base64 and zlib layers. When the code runs, it takes over the CryptoPay constructor. It sends the tokens and API server details passed to the client to the attacker's Telegram bot.

PyPI notes that the project's GitHub repository held clean code. The malware was only in the published packages. ReversingLabs reports more than 10,000 downloads before removal.

Affected versions

The advisory GHSA-486g-47cc-8wxf lists a severity of High (CVSS 8.3) and no CVE.

Indicators of compromise

ReversingLabs lists the hashes as a partial list. The sources do not give the bot token or chat id.

How to check

Check whether aiocpa is installed and which version.

pip show aiocpa

Search every environment, lockfile and requirements file for the package.

grep -rniE "aiocpa==?0\.1\.1[34]" . --include="*.txt" --include="*.lock" --include="*.toml"

Do not import the package to test it. Importing runs the obfuscated code.

What to do now

  1. Uninstall aiocpa from every environment with pip uninstall aiocpa.
  2. Revoke and replace every Crypto Pay API token that you passed to the client.
  3. Review your Crypto Pay account for unexpected activity.
  4. Pin dependency versions with hash checking so that an unexpected release cannot install silently.
  5. Monitor outbound network traffic from build and production hosts.

Vigilance compares the version you trust with a new one. Here, sync.py gained multi-layer decode-and-execute code and an outbound send of client arguments. That is a new capability in a file that held plain library code in 0.1.12.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old aiocpa-0.1.12 --new aiocpa-0.1.13
files scanned: 10

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    cryptopay/utils/sync.py
           It now reads saved passwords and access keys and runs other programs. It did not before.

Frequently asked questions

Which aiocpa versions are malicious?

Versions 0.1.13 and 0.1.14, both published on 20 November 2024. PyPI lists versions 0.1.0 through 0.1.12 as clean.

What did the aiocpa malware steal?

It sent the arguments that a developer passes when creating the Crypto Pay client, such as API tokens and server details, to a Telegram bot that the attacker controlled.

Is aiocpa still on PyPI?

No. PyPI quarantined the package on 21 November 2024 and then removed it.

Sources

  1. blog.pypi.org/posts/2024-11-25-aiocpa-attack-analysis/
  2. github.com/advisories/GHSA-486g-47cc-8wxf
  3. reversinglabs.com/blog/malicious-pypi-crypto-pay-package-aiocpa-implants-infostealer-code

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free