Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

bittensor-burn-alertPyPI

bittensor-burn-alert is a confirmed malicious PyPI package (MAL-2026-5330) that steals credentials and exfiltrates sensitive data (malicious versions 1.7.3, 1.7.4, 1.7.5). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in bittensor-burn-alert (PyPI)

MAL-2026-5330
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall bittensor-burn-alert

What this malware does

The package advertises itself as a Bittensor subnet burn-rate monitor but bundles a covert clipboard surveillance daemon in its compiled core module (bittensor_burn_watch/core.cpython-310-*.so). When the user runs the documented bittensor-burn-alert install command, the daemon installs persistence across all major operating systems — Windows Task Scheduler, Linux systemd user service, and macOS LaunchAgent — and starts polling the clipboard on every login. Clipboard contents are read via Win32 API on Windows (with a PowerShell fallback), wl-paste --watch on Wayland, and xclip on X11; the Linux path scrapes DISPLAY/DBUS_SESSION_BUS_ADDRESS from the active graphical session and auto-installs wl-clipboard/xclip if missing. Each unique clipboard string (deduplicated via SQLite) is POSTed to https://api.telegram.org against a hardcoded bot token (8666228137) and chat ID (8766781014) shipped in bittensor_burn_watch/defaults.env. A comment inside the compiled binary explicitly labels these credentials as 'Bundled clipboard Telegram + taostats API (all pip users; not user-editable)' — the exfiltration channel is intentionally separated from the user-facing BURN_TELEGRAM_* configuration so installers cannot redirect or disable it. The binary further notes 'no window flash' / 'no taskbar flash' to evade user awareness. The Bittensor-themed naming targets TAO subnet operators, whose clipboards routinely carry wallet seed phrases, addresses, and API keys.

The package contains code to steal clipboard content to a predefined remote location. If run in the right way, the code will periodically check the clipboard and if the content matches the pattern, exfiltrates it. Early versions contain this behavior mentioned in the README. The targeted data are likely cryptocurrency secret phrases.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-06-clip-logger

Reasons (based on the campaign):

  • clipboard-stealing

  • crypto-related

Malicious versions

3 flagged
1.7.31.7.41.7.5

Indicators of compromise (SHA-256)

fe199e0ca267ae05d6213339b5d925218af5b5c2d884dfb4c74bc99b81a19c0f
dff7daa35cef031719bab0430db9c62c319f671f8b23651506c5b54db6a7e409
56705160c9280ed8e047a6c397c6828e6e339775be7daca098eca431ee0f3b4a
06e89dc9ff0a5d334b67a01c572c036b0740adf6d8669d2fa25c241a0c098116
2530136b72ae3f2c52ec96f497809bfd2a2dcd12d80f973d367f7d993897bcd9
8034300a461f61577ede68abb7e883b0e7c18f3e882936a387e3111cd3b0459b

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for bittensor-burn-alert (3 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging bittensor-burn-alert across your stack and pipelines.

  2. If you installed it — respond

    bittensor-burn-alert is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If bittensor-burn-alert was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks bittensor-burn-alert before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. bittensor-burn-alert on PyPI has been identified as a malicious package (versions 1.7.3, 1.7.4, 1.7.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

2026-06-clip-loggerIN-MAL-2026-005642IN-MAL-2026-005645IN-MAL-2026-009499

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks bittensor-burn-alert-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

bittensor-burn-alert (PyPI) malicious package — MAL-2026-5330 | O3 Security