Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Mlflow Otel Instrumentor supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in cryptgraphy (PyPI)

    A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

    2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting