Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 11 Spellcheckers supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in pytablute (PyPI)

    The PyPI package pytablute contained malicious code that executes hidden functionality during import or use, downloads second-stage payloads, and establishes persistent remote command execution capabilities. The package was part of a broader 2025-11-spellcheckers malicious campaign.

    2025 11 SpellcheckersPyPICompromised package