Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 07 Cas Base Campaign supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in xxx-bale (PyPI)

    The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.

    2025 07 Cas Base CampaignPyPICompromised package