Social Engineering 2024 Incident #13

aiocpa backdoor

Estimated Financial Impact
Limited (12K downloads)
Blast Radius
Novel long-game; source-binary mismatch

What Happened

An attacker published a genuinely functional Crypto Pay API client on PyPI, built a user base over several months, then injected credential-stealing code. The GitHub source remained clean — only the PyPI-published version contained malware. This "long game" approach was considered novel at time of discovery.

✓

Risk Guard: Caught

PACKAGE_SOURCE_URL_MISMATCH detects PyPI artifact diverging from clean GitHub source

Risk Guard Check Codes That Flag This Incident

SOURCE_MALFORMED_METADATAPACKAGE_SOURCE_URL_MISMATCH

How Every Tool Performed

2 Caught 0 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_SOURCE_URL_MISMATCH detects PyPI artifact diverging from clean GitHub source
Socket Caught Source-binary mismatch detection
Snyk Missed No source-registry divergence detection
Sonatype (Nexus) Missed No source-registry divergence detection
Black Duck Missed No source-registry divergence detection
Endor Labs Missed No source-registry divergence detection
← XZ Utils backdoor (CVE-2024-3094) colors.js / faker.js sabotage →