Skip to content
supplychainattack.orgSupply chain attack incident catalog

Supply chain attack incidents

A neutral catalog of confirmed software, hardware, and vendor supply chain attacks, ordered by most recent update. Every entry is backed by at least one credible public advisory. Filter by ecosystem, attack vector, severity, status, or threat actor.

  1. activecritical

    Malware in app-data-layer

    The npm package app-data-layer was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  2. containedcritical

    Malware in app-node-layer

    Malware was discovered in the npm package app-node-layer. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  3. resolvedcritical

    Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

    PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.

    PyPICompromised package
  4. containedcritical

    Malware in app-data-ist

    The npm package app-data-ist was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  5. containedcritical

    Malware in app-data-lts

    The npm package app-data-lts was found to contain malware, potentially giving full control of affected systems to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  6. activecritical

    Malware in svgcraft-core

    Malware discovered in the npm package svgcraft-core. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  7. containedcritical

    Malware in fs-extra-core

    Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  8. containedcritical

    Malware in cktool-core

    Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  9. activecritical

    Malware in lychee-norm-cache

    Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  10. containedcritical

    Malware in da-sc-sdk

    Malware was discovered in the npm package da-sc-sdk. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a clean system.

    npmCompromised package
  11. activecritical

    Malware in helix-deploy

    Malware discovered in the npm package helix-deploy. Systems with this package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  12. containedcritical

    Malware in vue-demi-fix

    Malware was discovered in the npm package vue-demi-fix, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  13. containedcritical

    Malware in base65-85x

    The npm package base65-85x was found to contain malware, potentially giving full control of affected systems to an outside entity. All systems with this package installed should be considered fully compromised.

    npmCompromised package
  14. activecritical

    Malware in @bcryptln/becryptjs

    Malware discovered in the npm package @bcryptln/becryptjs. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  15. containedcritical

    Malware in streak-lib-math

    Malware was discovered in the npm package streak-lib-math. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  16. containedcritical

    Malware in streak-bucket-lib

    The npm package streak-bucket-lib was found to contain malware, potentially giving attackers full control of affected systems. All systems with this package installed should be considered compromised and all secrets/keys rotated from a clean machine.

    npmCompromised package
  17. containedcritical

    Malware in eth-slint

    Malware was discovered in the eth-slint npm package. Systems with the package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  18. containedcritical

    Malware in svelte-goal-streak

    Malware was discovered in the npm package svelte-goal-streak. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  19. containedcritical

    Malware in yuinpm

    The npm package yuinpm was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  20. containedcritical

    Malware in eth-base

    Malware was discovered in the eth-base npm package. Any computer with this package installed or running should be considered fully compromised, with all secrets and keys at risk.

    npmCompromised package
  21. activecritical

    Malware in chai-as-stringify

    Malware discovered in the npm package chai-as-stringify. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  22. containedcritical

    Malware in eth-codergen

    Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  23. containedcritical

    Malware in create-kumo-project

    Malware was discovered in the npm package create-kumo-project. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  24. activecritical

    Malware in xrblocks-remote-control

    The npm package xrblocks-remote-control contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  25. activecritical

    Malware in aio-commerce-lib-app

    Malware discovered in the npm package aio-commerce-lib-app. Any system with this package installed or running should be considered fully compromised.

    npmCompromised package
  26. containedcritical

    Malware in eslint-angular-react

    The npm package eslint-angular-react contained malware that could fully compromise any system where it was installed or executed. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  27. resolvedcritical

    Malware in mcp-notes-server-poc-praetorian

    The npm package mcp-notes-server-poc-praetorian contained malware that provided full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  28. activecritical

    Malware in bs58-88

    The npm package bs58-88 contains malware that provides full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  29. containedcritical

    Malware in ethers-wallet-package

    Malware was discovered in the npm package ethers-wallet-package, potentially providing full system compromise to attackers. All systems with this package installed should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  30. containedcritical

    Malware in svelte-streak-metrics

    Malware was discovered in the npm package svelte-streak-metrics. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  31. activecritical

    Malware in ethers-wallet-packages

    Malware was discovered in the npm package ethers-wallet-packages. Systems with this package installed are considered fully compromised and all secrets and keys should be rotated immediately from a different computer.

    npmCompromised package
  32. containedcritical

    Malware in ethers-packge

    The npm package ethers-packge contained malware that compromised any system where it was installed. Systems with this package should be considered fully compromised and all secrets and keys rotated from a different computer.

    npmCompromised package
  33. activecritical

    Malware in @bcryptln/bcryptjs

    The npm package @bcryptln/bcryptjs contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  34. activecritical

    Malware in vitest-axios

    The npm package vitest-axios contains malware that grants full system compromise to an outside entity. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  35. containedcritical

    Malicious code in intercom-php (Packagist)

    The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.

    Mini Shai HuludTeamPCPNuGetCompromised packageMalicious maintainer
  36. resolvedcritical

    Malware in veskr

    The npm package veskr contained malware that provided full system compromise to attackers. Any computer with the package installed or running should be considered fully compromised.

    npmCompromised package
  37. resolvedcritical

    Malware in veldora

    The npm package veldora contained malware that provided full system compromise to attackers. Any system with the package installed or running should be considered fully compromised.

    npmCompromised package
  38. containedcritical

    Malware in react-tabulix-core

    Malware was discovered in the npm package react-tabulix-core. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  39. activecritical

    Malware in react-tabulix-ui

    Malware discovered in the npm package react-tabulix-ui. Any computer with this package installed or running should be considered fully compromised. All secrets and keys must be rotated immediately from a different computer.

    npmCompromised package
  40. containedcritical

    Malware in encryptstringadmin

    The npm package encryptstringadmin was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  41. activecritical

    Malware in encryptstringadmincore

    Malware discovered in the npm package encryptstringadmincore. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  42. containedcritical

    Malware in caldryn

    Malware was discovered in the npm package caldryn, resulting in full system compromise for any computer with the package installed or running. All secrets and keys on affected systems should be rotated immediately from a different computer.

    npmCompromised package
  43. containedcritical

    Malware in calvora

    Malware was discovered in the npm package calvora, resulting in full system compromise of any computer with the package installed or running. All affected systems should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  44. containedcritical

    Malware in react-tabulix-query

    Malware was discovered in the npm package react-tabulix-query. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.

    npmCompromised package
  45. containedcritical

    Malware in kijai

    The npm package kijai was found to contain malware that grants full system compromise to attackers. Any system with this package installed or running should be considered fully compromised and all secrets and keys rotated immediately from a different computer.

    npmCompromised package
  46. activecritical

    Malware in vectormark

    The npm package vectormark contains malware that grants full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised and all secrets and keys should be rotated immediately from a different machine.

    npmCompromised package
  47. containedcritical

    Malware in fastify-bundler

    Malware was discovered in the npm package fastify-bundler, resulting in full system compromise for any installation. All affected systems should be considered fully compromised and all secrets rotated from a clean machine.

    npmCompromised package
  48. containedcritical

    Malware in calmora

    The npm package calmora was found to contain malware, resulting in full system compromise of any computer with the package installed or running. GitHub Security Advisory GHSA-7wwx-476f-c8gm documents the incident.

    npmCompromised package
  49. activecritical

    Malware in encrypt-string-ttak

    The npm package encrypt-string-ttak contains malware that provides full system compromise to attackers. Any computer with this package installed should be considered fully compromised and all secrets and keys rotated immediately from a different machine.

    npmCompromised package
  50. resolvedcritical

    Malware in vantora

    The npm package vantora contained malware that provided full system compromise to attackers. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package
  51. resolvedcritical

    Malicious code in adpost (PyPI)

    The adpost package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  52. resolvedcritical

    Malicious code in adm4 (PyPI)

    Malicious code was discovered in the adm4 package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  53. resolvedcritical

    Malicious code in adcandy (PyPI)

    The adcandy package on PyPI contained malicious code designed to execute spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  54. containedcritical

    Malicious code in zakuchienne (PyPI)

    The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.

    2025 11 MescouillesPyPICompromised package
  55. resolvedcritical

    Malicious code in adcraft (PyPI)

    The adcraft package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  56. resolvedcritical

    Malicious code in admine (PyPI)

    The PyPI package 'admine' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  57. resolvedcritical

    Malicious code in admcheck (PyPI)

    Malicious code was discovered in multiple versions of the admcheck package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  58. resolvedcritical

    Malicious code in adv2099m (PyPI)

    Malicious code was discovered in the adv2099m package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4734.

    PyPICompromised package
  59. resolvedcritical

    Malicious code in adv2099m4 (PyPI)

    Malicious code was discovered in the adv2099m4 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  60. resolvedcritical

    Malicious code in adtool (PyPI)

    The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  61. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  62. resolvedcritical

    Malicious code in adsplit (PyPI)

    The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  63. resolvedcritical

    Malicious code in xorg-renderproto (PyPI)

    Malicious code was discovered in the xorg-renderproto package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  64. resolvedcritical

    Malicious code in xolofyxkotqwko (PyPI)

    Malicious code was discovered in the PyPI package xolofyxkotqwko. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  65. containedcritical

    Malicious code in xxx-bale (PyPI)

    The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.

    2025 07 Cas Base CampaignPyPICompromised package
  66. resolvedhigh

    Malicious code in yeshsurya (PyPI)

    The yeshsurya package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  67. resolvedcritical

    Malicious code in yelp-cgeom1 (PyPI)

    The PyPI package yelp-cgeom1 version 0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    PyPICompromised package
  68. resolvedcritical

    Malicious code in yffinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yffinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  69. resolvedcritical

    Malicious code in xoloxwmellxliq (PyPI)

    Malicious code was discovered in the xoloxwmellxliq package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6248.

    PyPICompromised package
  70. resolvedcritical

    Malicious code in xologrekjlqzxj (PyPI)

    Malicious code was discovered in the xologrekjlqzxj package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  71. resolvedcritical

    Malicious code in xoloqmotdjpbic (PyPI)

    Malicious code was discovered in the xoloqmotdjpbic package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  72. resolvedcritical

    Malicious code in zipf (PyPI)

    Malicious code was discovered in the zipf package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  73. resolvedcritical

    Malicious code in znomig (PyPI)

    Malicious code was discovered in the znomig package on PyPI. The package contained intentional malicious functionality and was cataloged by the OpenSSF malicious packages database.

    PyPICompromised package
  74. resolvedcritical

    Malicious code in zyqnuutupjerllnbxaeq (PyPI)

    Malicious code was published in the zyqnuutupjerllnbxaeq package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  75. resolvedcritical

    Malicious code in xolosamsdyhcfa (PyPI)

    Malicious code was discovered in the xolosamsdyhcfa package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  76. resolvedcritical

    Malicious code in yfinancce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinancce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  77. resolvedcritical

    Malicious code in yfinnace (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnace, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  78. containedcritical

    Malicious code in xyq-drama-skill (PyPI)

    xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.

    PyPICompromised packageMalicious commit
  79. resolvedcritical

    Malicious code in yfinnce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnce, which infected local browsers with a malicious extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  80. resolvedcritical

    Malicious code in yellyproxies (PyPI)

    Malicious code was discovered in the yellyproxies package on PyPI. The package contained malicious functionality that could compromise systems of users who installed it.

    PyPICompromised package
  81. resolvedcritical

    Malicious code in yfiinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  82. resolvedcritical

    Malicious code in yfinacne (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinacne, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  83. containedhigh

    Malicious code in yhaplo1 (PyPI)

    Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.

    PyPIDependency confusionCompromised package
  84. resolvedcritical

    Malicious code in yfinannce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinannce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  85. containedcritical

    Malicious code in yeahmankema (PyPI)

    Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.

    2026 05 CrayrandomizPyPICompromised package
  86. resolvedcritical

    Malicious code in yfiannce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiannce, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  87. resolvedcritical

    Malicious code in yfinaance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinaance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  88. resolvedcritical

    Malicious code in yc-as-client (PyPI)

    The PyPI package yc-as-client version 11.11.3 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.

    PyPICompromised package
  89. resolvedcritical

    Malicious code in xxoo-bale (PyPI)

    The PyPI package xxoo-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload required a separate trigger to activate.

    2025 07 Cas BasePyPICompromised package
  90. resolvedcritical

    Malicious code in xxlsxwriter (PyPI)

    Malicious code was distributed in the xxlsxwriter package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious versions installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  91. resolvedhigh

    Malicious code in yc-depconf-test-807dff (PyPI)

    The PyPI package yc-depconf-test-807dff contains malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package
  92. resolvedcritical

    Malicious code in yfinace (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinace, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  93. resolvedcritical

    Malicious code in yfinancee (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinancee, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  94. resolvedcritical

    Malicious code in ytorch (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ytorch, designed to infect local browsers with malicious extensions. The malicious extension manipulates clipboard content and replaces cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets.

    PyPICompromised package
  95. containedcritical

    Malicious code in yolov8mini (PyPI)

    The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.

    PyPICompromised package
  96. resolvedcritical

    Malicious code in ython-binance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ython-binance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised packageTyposquatting
  97. resolvedcritical

    Malicious code in yvper (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yvper, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  98. resolvedcritical

    Malicious code in yyfinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  99. containedcritical

    Malicious code in yuzo (PyPI)

    The yuzo package on PyPI contained malicious code implementing an infostealer (CStealer-based) designed to exfiltrate browser data and other sensitive information to a hardcoded Discord webhook. Multiple versions of the package were affected with varying implementations of the malware.

    2025 09 SuyoPyPICompromised package
  100. resolvedcritical

    Malicious code in yfniance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package