2026 08 Flasq supply chain incidents
3 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.
- containedcritical
Malicious code in speed-hashes (PyPI)
Multiple malicious variants of the speed-hashes package were published to PyPI, containing obfuscated code that executes during installation. The malware downloads and executes remote binaries, exfiltrates cryptocurrency wallet data and other sensitive information, and achieves remote code execution on the installer's host.
2026 08 FlasqPyPICompromised packageTyposquatting - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package