Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 07 ML Shared supply chain incidents

4 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in ml-data-shared (PyPI)

    The ml-data-shared package on PyPI contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and cataloged as part of the 2026-07-ml-shared malicious campaign by the OpenSSF.

    2026 07 ML SharedPyPICompromised package
  2. resolvedcritical

    Malicious code in ml-nps-shared (PyPI)

    The PyPI package ml-nps-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.

    2026 07 ML SharedPyPICompromised package
  3. containedhigh

    Malicious code in ml-shared (PyPI)

    The PyPI package ml-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.

    2026 07 ML SharedPyPICompromised package
  4. resolvedhigh

    Malicious code in ml-fdbk-shared (PyPI)

    The PyPI package ml-fdbk-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported as part of the 2026-07-ml-shared malicious campaign.

    2026 07 ML SharedPyPICompromised package