Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 05 AI Labs Snippets Sdk supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedhigh

    Malicious code in ai-labs-snippets-sdk (PyPI)

    The ai-labs-snippets-sdk package on PyPI contained malicious code that exfiltrates system information (IP address, username, .gitconfig) to a remote target. The malicious payload was embedded as pickle-serialized code within a file disguised as an AI model, executed during package import.

    2025 05 AI Labs Snippets SdkPyPICompromised package