March 12, 2024, 12:13 p.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

Threat hunters have discovered a set of seven packages on the Python Package Index (PyPI) repository that are designed to steal BIP39 mnemonic phrases used for recovering private keys of a cryptocurrency wallet.
The software supply chain attack campaign has been codenamed BIPClip by ReversingLabs. The packages were collectively downloaded 7,451 times prior to them being removed from

attack bip39 campaign can crypto cryptocurrency cryptocurrency wallet crypto wallets hunters keys mnemonic package packages private private keys pypi python python package python package index python packages repository reversinglabs software software supply chain software supply chain attack steal supply supply chain supply chain attack threat wallet wallets watch

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Associate Compliance Advisor

@ SAP | Budapest, HU, 1031

DevSecOps Engineer

@ Qube Research & Technologies | London

Software Engineer, Security

@ Render | San Francisco, CA or Remote (USA & Canada)

Associate Consultant

@ Control Risks | Frankfurt, Hessen, Germany

Senior Security Engineer

@ Activision Blizzard | Work from Home - CA