Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ MAL-2026-13686 — chaintest

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in chaintest (PyPI)

Source: amazon-inspector

chaintest 0.1.0 on PyPI could not be fully characterized from the available artifacts. No concrete a static rule matches and no traced code evidence are available to identify a specific installer-harm mechanism (no named exfiltration endpoint, no install-time fetch-and-execute path, no credential-read path, no lifecycle-script behavior) in this record. Without a specific observed behavior to cite, the package's disposition is unresolved.

Source: kam193

The package contains a cryptocurrency infostealer that exfiltrates information from browsers (including cryptowallet extensions, synced extensions, local storage) and standalone applications (password managers, cryptowallets). The code achieves persistence via different methods on different platforms, and runs a keylogger that modifies the copied cryptocurrency addresses with addresses controlled by the attacker. Malicious code is also prepared to retrieve commands to execute from C2, exfiltrate SSH keys, and install malicious extensions in browsers.

The code shares some similarities with campaign 2026-07-cognikit attributed to the DPRK "Contagious Interview" campaign.

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-08-chaintest

Reasons (based on the campaign):

  • infostealer
  • clipboard-stealing
  • dependency-confusion
  • crypto-related
  • keylogger
  • exfiltration-browser-data
  • exfiltration-crypto
  • clipboard-modify
  • persistence
  • The package contains code to execute remote commands (probably limited to a specific set) on the victim's machine.
  • exfiltration-ssh-keys
  • files-exfiltration
  • rat

Affected software

MAL-2026-13686 is recorded against 1 package.

  • chaintest

Timeline and source

Published on 10 August 2026 and last revised on 11 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

Indicators of compromise

Domains: ephmral.info
IP addresses: 204.168.151.58

References

bad-packages.kam193.eu (Web)
pypi.org (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-08-10
Updated 2026-08-20
Modified 2026-08-11
Fix URL N/A

Affected Packages

Software From version Fixed in
chaintest

Free Vulnerability Check

Is your site affected by MAL-2026-13686?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-13686 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesMalicious packagesMalicious packages 2026