Skip to content
supplychainattack.orgSupply chain attack incident catalog

Esquelesquad supply chain incidents

9 confirmed incidents publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedcritical

    Malicious code in adsplit (PyPI)

    The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  2. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  3. resolvedcritical

    Malicious code in advm (PyPI)

    The advm package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  4. resolvedcritical

    Malicious code in adurl (PyPI)

    The adurl package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  5. resolvedcritical

    Malicious code in advirtual (PyPI)

    The advirtual package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  6. resolvedcritical

    Malicious code in adpull (PyPI)

    The adpull package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  7. resolvedcritical

    Malicious code in adram (PyPI)

    The PyPI package adram contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  8. resolvedcritical

    Malicious code in adpep (PyPI)

    The adpep package on PyPI contained malicious code as part of a campaign by EsqueleSquad group. The group published nearly 6,000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  9. resolvedcritical

    Malicious code in adultra (PyPI)

    The adultra package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package