Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 07 Telerape supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in telerape (PyPI)

    The telerape package on PyPI contained malicious code that placed a reverse shell in a PTH file, enabling arbitrary command execution on victim machines. The package was identified and cataloged as part of the 2026-07-telerape malicious campaign by the OpenSSF.

    2026 07 TelerapePyPICompromised package