GitHub Advisory PyPI CWE-506 sweep - 2-package 2026-08-02 batch (`trongriden@0.0.1` Tron/TRX cryptocurrency private-key exfiltration under the long-running `2025-04-tronix` campaign, `wacve-utils@1.0.7` Linux + Android/Termux encrypted infostealer with Telegram exfil)
GHSA published 2 PyPI CWE-506 advisories dated 2026-08-02: trongriden@0.0.1 - Tron/TRX cryptocurrency private-key exfiltration marked as part of the long-running 2025-04-tronix campaign - and wacve-utils@1.0.7, an encrypted infostealer targeting Linux and Android execution under Termux with file system / browser / SMS collection routed to a Telegram channel and remote-script download for dynamic payload updates.
- Detected by
- GitHub Advisory Database · OpenSSF Package Analysis · PyPI Security
- Also known as
- 2026-08-02 GHSA PyPI batch · 2025-04-tronix campaign resurgence · wacve-utils Telegram-exfil infostealer
- Ecosystems
- PyPI
- Packages tracked
- 2
What happened
On 2026-08-02, the GitHub Advisory Database published 2 new PyPI CWE-506 (Embedded Malicious Code) advisories in a same-day burst. This module catalogues that batch. Small batch - both advisories carry specific-behaviour prose (crypto-wallet key exfiltration campaign attribution, encrypted cross-platform infostealer with Telegram exfil) rather than the generic CWE-506 boilerplate, indicating GHSA / OpenSSF Package Analysis / vendor reverse-engineering observed the packages in dynamic analysis.
Cluster A - trongriden@0.0.1 Tron cryptocurrency private-key exfiltration (1 package, 2026-08-02)
| Package | Versions | Notes | |---|---|---| | trongriden | 0.0.1 | Tron/TRX private-key exfiltration, 2025-04-tronix campaign |
GHSA advisory records: "Package appears to be designed for private key exfiltration, but no known usage. The name appears to be related to the cryptocurrency TRX (Tron / Tronix)." Explicitly flagged as part of the 2025-04-tronix campaign - a long-running PyPI operator wave targeting Tron / TRX wallet infrastructure that has been re-surfacing throughout 2025 and 2026.
The advisory adds two campaign-behaviour notes: "some packages additionally clone the readme of other, legit libraries" (masquerade tactic - the operator scrapes a real Tron SDK / wallet library README and slaps it on the malicious package to increase plausibility during casual inspection) and "similar malicious packages … repeatedly uploaded to PyPI" (coordinated re-drop campaign, not isolated). The trongriden name shape (tron + griden - a corruption of "grid" / "gridden" that reads as a made-up product name) matches the operator's established pattern of tron<random-token> package names spread across 2025-2026.
trongriden is unlikely to catch a random developer install - the name is not a plausible typosquat of any real Tron library - so the operator is likely relying on casual pip-search / npm-search discovery by Tron-adjacent developers (Tron dApp devs, Tron wallet integrators) who scan PyPI for Tron tooling and install whatever surfaces without carefully verifying provenance.
Cluster B - wacve-utils@1.0.7 Linux + Android/Termux encrypted infostealer with Telegram exfil (1 package, 2026-08-02)
| Package | Version | Notes | |---|---|---| | wacve-utils | 1.0.7 | encrypted infostealer, Linux + Android (Termux), Telegram exfil, remote-script download |
GHSA advisory: "The package contains encrypted code with infostealers targeting Linux and Android (execution under Termux)." Full behaviour chain documented in the advisory prose:
- Encrypted payload: package ships obfuscated / encrypted code that decrypts and executes on install/import - defeats static-only detection tooling
- Cross-platform collection: file system contents, browser cookies / stored credentials, and SMS messages
- Telegram exfil channel: harvested data exfiltrates to an attacker-controlled Telegram bot / channel (a widely-abused persistent-exfil channel for Python infostealer families)
- Remote-script download: the payload additionally downloads and executes remote malicious scripts, enabling dynamic payload updates independent of the initial installation - the on-host malware version can be later than what GHSA analysed
The explicit Android-under-Termux targeting is unusual for PyPI malware and marks this as focused on mobile-red-team-adjacent developer environments. Termux is the standard Android terminal / package manager for security researchers, pentesters, CTF players, and bug bounty hunters who install Python packages on their Android devices - this operator is targeting that specific developer sub-population rather than generic PyPI consumers.
SMS collection on Android is especially notable: SMS-2FA interception is the single most valuable capability against banking, cryptocurrency exchange, and cloud-provider accounts that use SMS-based two-factor authentication. Any developer whose Android device installed wacve-utils in Termux should treat every SMS-2FA-linked account as compromised.
Registry state
Both packages security-yanked from PyPI during the 2026-08-02 takedown. Original version tarballs are no longer resolvable on the public index, but private mirrors (devpi, Artifactory, Nexus, AWS CodeArtifact, Google Artifact Registry) that cached tarballs BEFORE the takedown WILL keep serving the original versions.
Related tracked activity
- Cluster A
trongriden@0.0.1extends the long-running2025-04-tronixPyPI operator wave targeting Tron / TRX cryptocurrency infrastructure. The campaign has been documented by Snyk, Socket, and Phylum since April 2025 and re-surfaces sporadically with fresh package names. - Cluster B
wacve-utils@1.0.7extends the same encrypted-infostealer-with-Telegram-exfil pattern catalogued in the earlier 2026 PyPI sweeps - the specific Android-under-Termux targeting is distinctive. - The 2026-08-02 PyPI batch (2 packages, both with specific-behaviour prose) is quantitatively smaller than the 7-package 2026-08-01 batch (Cluster A
asdk-plugin-*dep-confusion trio, Cluster Bwalmart-genai-trace, Cluster CtelerapePTH-file reverse-shell, Cluster Dnvtorch-oot-nightly/trtllm-subdir-testNVIDIA-adjacent probe pair). Consistent with the pattern of PyPI publishing a big Monday batch followed by tail-end drops mid-week. - No
threatActorfield is set - GHSA advisories in this batch cite the2025-04-tronixcampaign name for Cluster A but do not name an actor.
Affected packages (2)
- PyPItrongriden0.0.1
- PyPIwacve-utils1.0.7
These are usually pulled in as transitive dependencies rather than installed directly. Check your whole tree at once - it runs in your browser and nothing is uploaded.
Impact
- Any host that installed either of the 2 PyPI packages listed below should be treated as fully compromised - every GHSA record uses CWE-506 with no patched version. Cluster A
trongridenis a crypto-wallet stealer - assume any TRX / Tron wallet key accessible from the host is compromised. Cluster Bwacve-utilsis a cross-platform infostealer with active Telegram exfil channel - assume browser cookies, file system contents, and SMS messages are already in attacker hands - Cluster A -
trongriden@0.0.1Tron cryptocurrency private-key exfiltration (1 package,= 0.0.1, 2026-08-02):trongriden. GHSA advisory: "Package appears to be designed for private key exfiltration, but no known usage. The name appears to be related to the cryptocurrency TRX (Tron / Tronix)." Explicitly flagged as part of the2025-04-tronixcampaign - a long-running PyPI operator wave targeting Tron / TRX wallet infrastructure that has been re-surfacing throughout 2025 and 2026. The advisory notes "some packages additionally clone the readme of other, legit libraries" (masquerade tactic) and confirms "similar malicious packages … repeatedly uploaded to PyPI" (coordinated distribution, not isolated) - Cluster B -
wacve-utils@1.0.7Linux + Android/Termux encrypted infostealer with Telegram exfil (1 package,= 1.0.7, 2026-08-02):wacve-utils. GHSA advisory: "The package contains encrypted code with infostealers targeting Linux and Android (execution under Termux)." Behaviour: encrypted payload that decrypts and executes on install/import; scrapes file system, browser cookies, and SMS messages; exfiltrates to a Telegram channel (attacker-controlled bot); downloads and executes remote malicious scripts for dynamic payload updates independent of the initial installation. Explicit Android-under-Termux targeting is unusual for PyPI malware and indicates operator focus on mobile-red-team-adjacent developer environments - Termux is the standard Android terminal / package manager for security researchers, pentesters, and CTF players who install Python packages on their Android devices - Neither package retains original tarballs on PyPI - both yanked during the 2026-08-02 takedown. Private mirrors that cached tarballs BEFORE the takedown WILL keep serving the original versions
What to do
- 1Grep every lockfile (
requirements.txt,Pipfile.lock,poetry.lock,uv.lock,pdm.lock,conda-lock.yml) for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the affected process could reach and re-image the host - 2Cluster A (
trongriden@0.0.1): any lockfile hit on any host that runs a Tron / TRX wallet, holds Tron-network private keys, or interacts with Tron dApps - treat every Tron wallet key on the host as compromised. Move remaining TRX and TRC-20 balances to a fresh cold wallet from an uncompromised device, revoke any Tron-network allowances, and rotate every credential the affected process could reach. The2025-04-tronixcampaign is long-running - audit allpip installhistory since April 2025 for other Tron-named packages (see the Snyk / Socket Tron-campaign coverage for the wider affected-package list) - 3Cluster B (
wacve-utils@1.0.7): any lockfile orpip freezehit - treat browser cookies, file system contents, and SMS messages as already exfiltrated to a Telegram channel. Log the affected user out of every browser session on the host (Google, Microsoft, GitHub, banking, crypto exchanges), rotate every credential the affected process could reach, invalidate any SMS-2FA-linked accounts, and re-image the host. Android developers running Termux: auditpkghistory andpip freezeon every Termux instance, and treat any hit as a full mobile-device compromise (re-flash if the device holds sensitive accounts). The remote-script-download vector means the payload could have been updated multiple times since 2026-08-02 - assume the current on-host malware version is later than what GHSA analysed - 4For all PyPI installs in CI, prefer
pip install --require-hasheswith a fully-hashedrequirements.txtor Poetry / uv / pdm lockfiles that pin resolved hashes - hash-pinning defeats swap-of-resolved-package with a same-name malicious package after initial resolution - 5Verify neither package still resolves via your private mirror - internal caches routinely keep serving yanked tarballs after the public takedown
References
- GitHubGitHub Advisory Database - recent PyPI malware advisoriesgithub.com
- GitHubGHSA-fgg6-xq4r-cp2h - trongriden malware advisory (2025-04-tronix Tron/TRX private-key exfil campaign)github.com
- GitHubGHSA-6wp2-7xxw-m8c6 - wacve-utils malware advisory (Linux + Android/Termux encrypted infostealer, Telegram exfil)github.com