Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Bigtime Campaign supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in bigtime (PyPI)

    The bigtime package on PyPI contained malicious code designed to exfiltrate data by overwriting the built-in "open" function and monitoring file writes. The package also attached watchers to files in the user's home directory to capture sensitive information.

    2026 08 Bigtime CampaignPyPICompromised package