Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Libasync supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in libasync (PyPI)

    The PyPI package libasync contained malicious code in a native extension that downloads and executes remote binaries, establishes persistence via registry keys, and performs cryptomining. The package was part of the 2026-08-libasync campaign and has been identified and documented by the OpenSSF.

    2026 08 LibasyncPyPICompromised package