THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·osv

Malicious code in bittensor-burn-monitor (PyPI)

bittensor-burn-monitor

Risk score

92

AI summary

Indexed incident for bittensor-burn-monitor (pypi).

Description

The package contains code to steal clipboard content to a predefined remote location. If run in the right way, the code will periodically check the clipboard and if the content matches the pattern, exfiltrates it. Early versions contain this behavior mentioned in the README. The targeted data are likely cryptocurrency secret phrases.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-clip-logger

Reasons (based on the campaign):

  • clipboard-stealing

  • crypto-related

Technical details

Affected versions

=1.5.0=1.5.3=1.5.5=1.6.0=1.6.3=1.6.5=1.7.0

Indicators

  • affected version=1.5.075%
  • affected version=1.5.375%
  • affected version=1.5.575%
  • affected version=1.6.075%
  • affected version=1.6.375%
  • affected version=1.6.575%
  • affected version=1.7.075%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents