Skip to content
supplychainattack.orgSupply chain attack incident catalog

2024 07 Weaponized Golden supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in a-oder (PyPI)

    Malicious code was published in the a-oder package on PyPI as part of the 2024-07-weaponized-golden campaign. The malware was designed for file exfiltration. The package has been identified and documented by the OpenSSF malicious-packages project.

    2024 07 Weaponized GoldenPyPICompromised package