March 12, 2024, 12:13 p.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

Threat hunters have discovered a set of seven packages on the Python Package Index (PyPI) repository that are designed to steal BIP39 mnemonic phrases used for recovering private keys of a cryptocurrency wallet.
The software supply chain attack campaign has been codenamed BIPClip by ReversingLabs. The packages were collectively downloaded 7,451 times prior to them being removed from

attack bip39 campaign can crypto cryptocurrency cryptocurrency wallet crypto wallets hunters keys mnemonic package packages private private keys pypi python python package python package index python packages repository reversinglabs software software supply chain software supply chain attack steal supply supply chain supply chain attack threat wallet wallets watch

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)