Fake PyPI library promising MEXC support hijacks API keys, redirects cryptocurrency orders, and steals user tokens from the legitimate CCXT library.