Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

ethereum-input-decorderPyPI

ethereum-input-decorder is a confirmed malicious PyPI package (MAL-2026-10643) that steals credentials and exfiltrates sensitive data (malicious versions 1.2.2, 1.2.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in ethereum-input-decorder (PyPI)

MAL-2026-10643
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall ethereum-input-decorder

What this malware does

The package name typosquats the legitimate 'ethereum-input-decoder'. Its top-level init.py unconditionally invokes a payload routine on import: it detects OS/arch, downloads a platform-specific binary from easyswapnow.pro (Linux/macOS builds at /downloads/lix_amd.bin, lix_arm.bin, mac_amd.bin, mac_arm.bin) or a Google Drive file for Windows, writes it to disk, sets the executable bit, and runs it via subprocess.run. The same import path also installs login persistence, writing ~/.config/systemd/user/python-script.service on Linux (enabled via systemctl --user enable --now) and ~/Library/LaunchAgents/com.user.script.plist on macOS (loaded via launchctl load -w), causing the dropper to re-run at every user login. setup.py ships placeholder author metadata ('Your Name', '[email protected]') and a 'Hello World on import' description, contradicting the README which advertises an eth_defi demo; none of this matches the actual dropper. The destination domain easyswapnow.pro is unrelated to the advertised Ethereum-decoding purpose.

The typosquatted package installs a Mythic/Poseidon C2 framework beacon and ensures persistence. After installation, the beacon communicates with C2 on wegoexchange[.]site for further commands.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-07-tennacity

Reasons (based on the campaign):

  • typosquatting

  • Downloads and executes a remote executable.

  • The package contains code to detect if it is running in a sandbox environment.

  • malware

  • persistence

Malicious versions

2 flagged
1.2.21.2.4

Indicators of compromise (SHA-256)

00564c1a112d6de4089e6f15e5c4a40b7975579811424b1e4fe2aebef7486a8f
94137fcf0aee7d8edb4e15a8bc9be4455fbdf79cb5bf99987b79f0393fdff62c
00437c563c5b7c2555d512f0066e6bdb5dc61300fd00027d1b5f0fc92a06d204
381c2db4c332b204ea25dcf08e4930a5f291918377816fa7305b68e3cd26134e
da0d9e54f086e668f4b4478684c8accf45a1f34a641058fd526b50f5a9060ace

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for ethereum-input-decorder (2 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging ethereum-input-decorder across your stack and pipelines.

  2. If you installed it — respond

    ethereum-input-decorder is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If ethereum-input-decorder was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks ethereum-input-decorder before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. ethereum-input-decorder on PyPI has been identified as a malicious package (versions 1.2.2, 1.2.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-010607IN-MAL-2026-0106082026-07-tennacity

References

Credits

  • Amazon Inspector · finder
  • Kamil Mańkowski (kam193) · reporter

Detect & block this

O3 blocks ethereum-input-decorder-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

ethereum-input-decorder (PyPI) malicious package — MAL-2026-10643 | O3 Security