Skip to content
supplychainattack.orgSupply chain attack incident catalog

2025 12 AI Cypher supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in ai-cypher (PyPI)

    The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.

    2025 12 AI CypherPyPICompromised package