Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 05 Crayrandomiz supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in yeahmankema (PyPI)

    Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.

    2026 05 CrayrandomizPyPICompromised package