Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 08 K7eel supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in xwormclient (PyPI)

    The xwormclient package on PyPI contained malicious code that downloads and executes a remote executable upon import. The package was identified as part of campaign 2025-08-k7eel and has been flagged by the OpenSSF malicious packages database.

    2025 08 K7eelPyPICompromised package