An attacker published a genuinely functional Crypto Pay API client on PyPI, built a user base over several months, then injected credential-stealing code. The GitHub source remained clean — only the PyPI-published version contained malware. This "long game" approach was considered novel at time of discovery.
PACKAGE_SOURCE_URL_MISMATCH detects PyPI artifact diverging from clean GitHub source
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_SOURCE_URL_MISMATCH detects PyPI artifact diverging from clean GitHub source |
| Socket | Caught | Source-binary mismatch detection |
| Snyk | Missed | No source-registry divergence detection |
| Sonatype (Nexus) | Missed | No source-registry divergence detection |
| Black Duck | Missed | No source-registry divergence detection |
| Endor Labs | Missed | No source-registry divergence detection |