Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Flasq Campaign supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in fast-hashes (PyPI)

    A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.

    2026 08 Flasq CampaignPyPITyposquattingCompromised package