Skip to content
supplychainattack.orgSupply chain attack incident catalog

2026 08 Neutrl Core supply chain incidents

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. containedcritical

    Malicious code in plp-contract (PyPI)

    The PyPI package plp-contract intentionally depends on a malicious package (neutrl-core) designed to exfiltrate sensitive credentials including environment variables, SSH keys, and dotenv files. The malicious code is disguised as telemetry and activates via remote command delivery from an attacker-controlled endpoint.

    2026 08 Neutrl CorePyPICompromised packageDependency confusion