Skip to content
supplychainattack.orgSupply chain attack incident catalog

PyPI supply chain incidents

234 confirmed incidents affecting the pypi ecosystem.

  1. containedhigh

    Malicious code in asdk-plugin-alphagen (PyPI)

    Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.

    PyPICompromised package
  2. resolvedhigh

    Malicious code in asdk-plugin-ai-platform (PyPI)

    The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package
  3. resolvedhigh

    Malicious code in asdk-plugin-legacy (PyPI)

    Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in telerape (PyPI)

    The telerape package on PyPI contained malicious code that placed a reverse shell in a PTH file, enabling arbitrary command execution on victim machines. The package was identified and cataloged as part of the 2026-07-telerape malicious campaign by the OpenSSF.

    2026 07 TelerapePyPICompromised package
  5. resolvedcritical

    Malicious code in ml-data-shared (PyPI)

    The ml-data-shared package on PyPI contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and cataloged as part of the 2026-07-ml-shared malicious campaign by the OpenSSF.

    2026 07 ML SharedPyPICompromised package
  6. resolvedcritical

    Malicious code in ml-nps-shared (PyPI)

    The PyPI package ml-nps-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.

    2026 07 ML SharedPyPICompromised package
  7. containedcritical

    Malicious code in aichannel (PyPI)

    Multiple malicious PyPI packages (aichannel, cognikit, aiassistcore) were published as part of a coordinated campaign attributed to North Korea's "Contagious Interview" operation. The packages contain infostealer functionality including cryptocurrency wallet address replacement, browser data exfiltration, keylogging, clipboard monitoring, and remote access capabilities.

    Contagious InterviewPyPICompromised packageMalicious commit
  8. containedhigh

    Malicious code in ml-shared (PyPI)

    The PyPI package ml-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.

    2026 07 ML SharedPyPICompromised package
  9. resolvedhigh

    Malicious code in ml-fdbk-shared (PyPI)

    The PyPI package ml-fdbk-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported as part of the 2026-07-ml-shared malicious campaign.

    2026 07 ML SharedPyPICompromised package
  10. containedcritical

    Malicious code in ailaunchkit (PyPI)

    A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  11. containedcritical

    Malicious code in aiassistcore (PyPI)

    Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  12. resolvedcritical

    Malicious code in reguestsc (PyPI)

    A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.

    PyPITyposquattingCompromised package
  13. resolvedhigh

    Malicious code in walmart-genai-trace (PyPI)

    walmart-genai-trace, a malicious package on PyPI, exfiltrates basic host information (IP, username) upon installation or import. The package overrides the install command in setup.py to execute malicious code during installation.

    PyPICompromised package
  14. containedcritical

    Malicious code in catalogai (PyPI)

    Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  15. containedcritical

    Malicious code in aiprepkit (PyPI)

    Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  16. containedcritical

    Malicious code in cognikit (PyPI)

    Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  17. resolvedhigh

    Malicious code in phabricator-client (PyPI)

    The phabricator-client package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  18. containedcritical

    Malicious code in mcp-search-server (PyPI)

    mcp-search-server on PyPI contained malicious code in versions published from July 2026 onward. The package included hidden "phone home" functionality disguised as a "share compute swarm" feature, and was part of a coordinated campaign with another malicious package designed to deploy coin miners on user machines.

    PyPICompromised packageMalicious maintainer
  19. containedcritical

    Malicious code in ai-perf-toolkit (PyPI)

    The PyPI package ai-perf-toolkit contained malicious code that initiates cryptomining for a hardcoded wallet upon import. The malicious campaign was identified and attributed to OpenSSF's malicious-packages repository.

    PyPICompromised package
  20. containedcritical

    Malicious code in dev-helper-bg (PyPI)

    The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.

    2026 07 Make HelperPyPICompromised packageMalicious commit
  21. resolvedcritical

    Malicious code in vtranalytic (PyPI)

    The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.

    PyPICompromised packageMalicious maintainer
  22. containedcritical

    Malicious code in karpatkit (PyPI)

    The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit
  23. containedcritical

    Malicious code in mrmustard (PyPI)

    A malicious version of the mrmustard package was published to PyPI containing code that exfiltrates SSH keys, AWS credentials, Kubernetes config, environment variables, and system identifiers to a remote endpoint. The payload includes multiple persistence mechanisms that survive package uninstallation.

    PyPICompromised package
  24. containedcritical

    Malicious code in karpatkey (PyPI)

    The karpatkey package on PyPI contained malicious code that exfiltrated sensitive credentials and data from infected systems. Upon import, the package spawned a background daemon thread that collected SSH keys, AWS/GCP credentials, kubeconfig, cryptocurrency wallets, and other secrets, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit
  25. containedcritical

    Malicious code in govapkg (PyPI)

    govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.

    PyPICompromised packageMalicious commit
  26. resolvedcritical

    Malicious code in cfgzen (PyPI)

    Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.

    2026 07 CfgzenPyPICompromised package
  27. resolvedcritical

    Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

    PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.

    PyPICompromised package
  28. resolvedcritical

    Malicious code in yfinnace (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnace, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  29. resolvedcritical

    Malicious code in yfinanec (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinanec, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  30. resolvedcritical

    Malicious code in yelp-pkg (PyPI)

    yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.

    PyPICompromised packageTyposquatting
  31. resolvedhigh

    Malicious code in xx-ent-wiki-sm (PyPI)

    The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  32. resolvedcritical

    Malicious code in xwormclient (PyPI)

    The xwormclient package on PyPI contained malicious code that downloads and executes a remote executable upon import. The package was identified as part of campaign 2025-08-k7eel and has been flagged by the OpenSSF malicious packages database.

    2025 08 K7eelPyPICompromised package
  33. resolvedcritical

    Malicious code in yellorq (PyPI)

    Malicious code was discovered in the yellorq package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing intentional malicious functionality.

    PyPICompromised package
  34. resolvedcritical

    Malicious code in xuiniadb (PyPI)

    Malicious code was discovered in the xuiniadb package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  35. resolvedcritical

    Malicious code in yfiance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  36. resolvedcritical

    Malicious code in ysocks (PyPI)

    Malicious code was distributed in the ysocks package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  37. resolvedcritical

    Malicious code in ypj (PyPI)

    Malicious code was discovered in the ypj package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  38. resolvedcritical

    Malicious code in ypinstaller (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ypinstaller, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  39. resolvedcritical

    Malicious code in ytest-cov (PyPI)

    Malicious code was discovered in the ytest-cov package on PyPI. The package contained malicious payload that could compromise systems of users who installed it.

    PyPICompromised package
  40. containedcritical

    Malicious code in yt-api-dlp (PyPI)

    yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.

    PyPITyposquattingCompromised package
  41. resolvedcritical

    Malicious code in youtubebot (PyPI)

    Malicious code was discovered in the youtubebot package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6251.

    PyPICompromised package
  42. resolvedcritical

    Malicious code in ypthon-binance (PyPI)

    Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised packageTyposquatting
  43. resolvedhigh

    Malicious code in zabitog (PyPI)

    Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.

    PyPICompromised packageDependency confusion
  44. resolvedcritical

    Malicious code in zakuraweb (PyPI)

    The zakuraweb package on PyPI contained malicious code that exfiltrates Discord tokens upon import. The package was identified as part of the 2025-11-morosint campaign and has been documented by the OpenSSF malicious packages repository.

    2025 11 MorosintPyPICompromised package
  45. resolvedcritical

    Malicious code in zeubilamouche (PyPI)

    Malicious code was discovered in the zeubilamouche package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  46. resolvedcritical

    Malicious code in zlib1g-dev (PyPI)

    Malicious code was discovered in the zlib1g-dev package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.

    PyPICompromised package
  47. resolvedhigh

    Malicious code in zero123 (PyPI)

    Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.

    PyPICompromised packageTyposquatting
  48. containedcritical

    Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)

    The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 contained malicious code that downloads and executes remote backdoor trojans during installation when run under specific usernames. The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior.

    PyPICompromised package
  49. resolvedcritical

    Malicious code in zenomenallib (PyPI)

    zenomenallib, a PyPI package, contained malicious code designed to exfiltrate sensitive files. The malicious payload was embedded in different locations across variants: module import, native binaries, or setup.py scripts. The package was identified and cataloged as part of the 2025-08-xenlib campaign.

    2025 08 XenlibPyPICompromised package
  50. resolvedcritical

    Malicious code in zlsrc (PyPI)

    Malicious code was discovered in the zlsrc package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6626.

    PyPICompromised package
  51. resolvedcritical

    Malicious code in zmaker (PyPI)

    A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.

    PyPICompromised packageMalicious commit
  52. resolvedcritical

    Malicious code in 3web-py (PyPI)

    The PyPI package 3web-py contained malicious code designed to function as an infostealer. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.

    Funcaptcha RU CampaignPyPICompromised package
  53. resolvedcritical

    Malicious code in 3-0 (PyPI)

    Malicious code was discovered in the 3-0 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  54. resolvedcritical

    Malicious code in 3web (PyPI)

    The PyPI package 3web contained malicious code designed to steal information. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.

    Funcaptcha RUPyPICompromised package
  55. resolvedcritical

    Malicious code in 7miners (PyPI)

    The 7miners package on PyPI contained malicious code designed to clone legitimate libraries with modifications. The package downloads and executes arbitrary remote code via Telegram as a command-and-control channel.

    2026 03 PipipipiPyPICompromised packageTyposquatting
  56. resolvedcritical

    Malicious code in adad (PyPI)

    The PyPI package 'adad' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  57. resolvedcritical

    Malicious code in aclient-sdk (PyPI)

    aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.

    PyPICompromised packageMalicious commit
  58. resolvedcritical

    Malicious code in a1rn (PyPI)

    Malicious code was discovered in the a1rn package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4729.

    PyPICompromised package
  59. resolvedcritical

    Malicious code in a3s-code (PyPI)

    The a3s-code PyPI package contained malicious code that fetched and executed native binaries (.so/.pyd/.dylib) from a GitHub organization (A3S-Lab) distinct from the documented project (AI45Lab), bypassing pip build isolation and hash verification.

    PyPICompromised packageTyposquatting
  60. resolvedhigh

    Malicious code in acpi-tables (PyPI)

    The acpi-tables package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.

    PyPICompromised package
  61. resolvedhigh

    Malicious code in adanbu (PyPI)

    The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  62. resolvedcritical

    Malicious code in acloud-client-uses (PyPI)

    A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.

    PyPICompromised packageTyposquatting
  63. resolvedcritical

    Malicious code in adgame (PyPI)

    The adgame package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  64. resolvedcritical

    Malicious code in adload (PyPI)

    The adload package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  65. resolvedcritical

    Malicious code in adgrand (PyPI)

    The adgrand package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  66. resolvedcritical

    Malicious code in adpost (PyPI)

    The adpost package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  67. resolvedcritical

    Malicious code in adm4 (PyPI)

    Malicious code was discovered in the adm4 package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  68. resolvedcritical

    Malicious code in adcandy (PyPI)

    The adcandy package on PyPI contained malicious code designed to execute spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  69. containedcritical

    Malicious code in zakuchienne (PyPI)

    The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.

    2025 11 MescouillesPyPICompromised package
  70. resolvedcritical

    Malicious code in adcraft (PyPI)

    The adcraft package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  71. resolvedcritical

    Malicious code in admine (PyPI)

    The PyPI package 'admine' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  72. resolvedcritical

    Malicious code in admcheck (PyPI)

    Malicious code was discovered in multiple versions of the admcheck package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  73. resolvedcritical

    Malicious code in adv2099m (PyPI)

    Malicious code was discovered in the adv2099m package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4734.

    PyPICompromised package
  74. resolvedcritical

    Malicious code in adv2099m4 (PyPI)

    Malicious code was discovered in the adv2099m4 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  75. resolvedcritical

    Malicious code in adtool (PyPI)

    The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  76. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  77. resolvedcritical

    Malicious code in adsplit (PyPI)

    The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  78. resolvedcritical

    Malicious code in xorg-renderproto (PyPI)

    Malicious code was discovered in the xorg-renderproto package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  79. resolvedcritical

    Malicious code in xolofyxkotqwko (PyPI)

    Malicious code was discovered in the PyPI package xolofyxkotqwko. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  80. containedcritical

    Malicious code in xxx-bale (PyPI)

    The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.

    2025 07 Cas Base CampaignPyPICompromised package
  81. resolvedhigh

    Malicious code in yeshsurya (PyPI)

    The yeshsurya package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  82. resolvedcritical

    Malicious code in yelp-cgeom1 (PyPI)

    The PyPI package yelp-cgeom1 version 0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

    PyPICompromised package
  83. resolvedcritical

    Malicious code in yffinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yffinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  84. resolvedcritical

    Malicious code in xoloxwmellxliq (PyPI)

    Malicious code was discovered in the xoloxwmellxliq package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6248.

    PyPICompromised package
  85. resolvedcritical

    Malicious code in xologrekjlqzxj (PyPI)

    Malicious code was discovered in the xologrekjlqzxj package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  86. resolvedcritical

    Malicious code in xoloqmotdjpbic (PyPI)

    Malicious code was discovered in the xoloqmotdjpbic package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.

    PyPICompromised package
  87. resolvedcritical

    Malicious code in zipf (PyPI)

    Malicious code was discovered in the zipf package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  88. resolvedcritical

    Malicious code in znomig (PyPI)

    Malicious code was discovered in the znomig package on PyPI. The package contained intentional malicious functionality and was cataloged by the OpenSSF malicious packages database.

    PyPICompromised package
  89. resolvedcritical

    Malicious code in zyqnuutupjerllnbxaeq (PyPI)

    Malicious code was published in the zyqnuutupjerllnbxaeq package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  90. resolvedcritical

    Malicious code in xolosamsdyhcfa (PyPI)

    Malicious code was discovered in the xolosamsdyhcfa package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  91. resolvedcritical

    Malicious code in yfinancce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinancce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  92. containedcritical

    Malicious code in xyq-drama-skill (PyPI)

    xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.

    PyPICompromised packageMalicious commit
  93. resolvedcritical

    Malicious code in yfinnce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnce, which infected local browsers with a malicious extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  94. resolvedcritical

    Malicious code in yellyproxies (PyPI)

    Malicious code was discovered in the yellyproxies package on PyPI. The package contained malicious functionality that could compromise systems of users who installed it.

    PyPICompromised package
  95. resolvedcritical

    Malicious code in yfiinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  96. resolvedcritical

    Malicious code in yfinacne (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinacne, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  97. containedhigh

    Malicious code in yhaplo1 (PyPI)

    Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.

    PyPIDependency confusionCompromised package
  98. resolvedcritical

    Malicious code in yfinannce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinannce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  99. containedcritical

    Malicious code in yeahmankema (PyPI)

    Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.

    2026 05 CrayrandomizPyPICompromised package
  100. resolvedcritical

    Malicious code in yfiannce (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfiannce, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  101. resolvedcritical

    Malicious code in yfinaance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinaance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  102. resolvedcritical

    Malicious code in yc-as-client (PyPI)

    The PyPI package yc-as-client version 11.11.3 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.

    PyPICompromised package
  103. resolvedcritical

    Malicious code in xxoo-bale (PyPI)

    The PyPI package xxoo-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload required a separate trigger to activate.

    2025 07 Cas BasePyPICompromised package
  104. resolvedcritical

    Malicious code in xxlsxwriter (PyPI)

    Malicious code was distributed in the xxlsxwriter package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious versions installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  105. resolvedhigh

    Malicious code in yc-depconf-test-807dff (PyPI)

    The PyPI package yc-depconf-test-807dff contains malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package
  106. resolvedcritical

    Malicious code in yfinace (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinace, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  107. resolvedcritical

    Malicious code in yfinancee (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinancee, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  108. resolvedcritical

    Malicious code in ytorch (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ytorch, designed to infect local browsers with malicious extensions. The malicious extension manipulates clipboard content and replaces cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets.

    PyPICompromised package
  109. containedcritical

    Malicious code in yolov8mini (PyPI)

    The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.

    PyPICompromised package
  110. resolvedcritical

    Malicious code in ython-binance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ython-binance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised packageTyposquatting
  111. resolvedcritical

    Malicious code in yvper (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yvper, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  112. resolvedcritical

    Malicious code in yyfinance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  113. containedcritical

    Malicious code in yuzo (PyPI)

    The yuzo package on PyPI contained malicious code implementing an infostealer (CStealer-based) designed to exfiltrate browser data and other sensitive information to a hardcoded Discord webhook. Multiple versions of the package were affected with varying implementations of the malware.

    2025 09 SuyoPyPICompromised package
  114. resolvedcritical

    Malicious code in yfniance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  115. resolvedcritical

    Malicious code in youtube-new (PyPI)

    Malicious code was discovered in the youtube-new package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41801.

    PyPICompromised package
  116. resolvedcritical

    Malicious code in youreallydontwantthispackage2132 (PyPI)

    Malicious code was published in the PyPI package youreallydontwantthispackage2132 version 1.0.3. The package executes malicious code during installation via setup.py override and communicates with domains associated with malicious activity, exfiltrating environment variables and other data.

    PyPICompromised packageTyposquatting
  117. resolvedcritical

    Malicious code in ypcodestyle (PyPI)

    Malicious code was distributed in the ypcodestyle package on PyPI as part of a campaign distributing 900+ compromised packages. The malware installs a malicious browser extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  118. resolvedcritical

    Malicious code in yzip (PyPI)

    The yzip package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and infosteal capabilities, tracked as campaign 2025-11-uzip.

    2025 11 UzipPyPICompromised package
  119. resolvedcritical

    Malicious code in zafira (PyPI)

    Malicious code was discovered in the zafira package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6252.

    PyPICompromised package
  120. resolvedcritical

    Malicious code in ypsocks (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ypsocks, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  121. resolvedhigh

    Malicious code in your-module-name (PyPI)

    The your-module-name package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  122. resolvedcritical

    Malicious code in yper (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yper, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  123. resolvedhigh

    Malicious code in yt-yson-bindings (PyPI)

    The yt-yson-bindings package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  124. resolvedcritical

    Malicious code in ziggonext (PyPI)

    Malicious code was discovered in the ziggonext package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6623.

    PyPICompromised package
  125. resolvedcritical

    Malicious code in zamino (PyPI)

    The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.

    2025 06 SorexPyPICompromised packageTyposquatting
  126. resolvedcritical

    Malicious code in zlapp (PyPI)

    Malicious code was discovered in the zlapp package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  127. activecritical

    Malicious code in zhopaorlaaato (PyPI)

    The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.

    PyPICompromised package
  128. resolvedcritical

    Malicious code in zatta (PyPI)

    Malicious code was discovered in the zatta package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6253.

    PyPICompromised package
  129. resolvedhigh

    Malicious code in zip-me (PyPI)

    The PyPI package zip-me contained malicious code designed to exfiltrate system information including IP address and username. The malware was activated during package installation via a metaclass override in setup.py and employed VM-detection techniques to avoid analysis.

    2024 12 Langer UpdaterPyPICompromised package
  130. resolvedcritical

    Malicious code in zefkopzekfo (PyPI)

    Malicious code was discovered in the zefkopzekfo package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6254.

    PyPICompromised package
  131. resolvedcritical

    Malicious code in zhpt1cscoe (PyPI)

    Malicious code was discovered in the zhpt1cscoe package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6257.

    PyPICompromised package
  132. resolvedcritical

    Malicious code in zelixnitro (PyPI)

    Malicious code was discovered in the zelixnitro package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  133. resolvedcritical

    Malicious code in ziugxfbvo (PyPI)

    The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.

    2026 04 Process SupportPyPICompromised package
  134. resolvedcritical

    Malicious code in zproxy2 (PyPI)

    Malicious code was discovered in the zproxy2 package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  135. resolvedcritical

    Malicious code in zscaner (PyPI)

    A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.

    PyPICompromised packageMalicious commit
  136. resolvedcritical

    Malicious code in zorosnitro (PyPI)

    Malicious code was discovered in the zorosnitro package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  137. resolvedcritical

    Malicious code in zlibxjson (PyPI)

    Malicious code was published in the zlibxjson package on PyPI as part of the zlibxjson-discord-cookies campaign. The package contained infostealer functionality designed to steal Discord cookies and other sensitive data from infected systems.

    Zlibxjson Discord CookiesPyPICompromised package
  138. resolvedcritical

    Malicious code in zproxy (PyPI)

    Malicious code was discovered in the zproxy package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  139. resolvedcritical

    Malicious code in adpull (PyPI)

    The adpull package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  140. resolvedcritical

    Malicious code in adram (PyPI)

    The PyPI package adram contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  141. resolvedcritical

    Malicious code in adpep (PyPI)

    The adpep package on PyPI contained malicious code as part of a campaign by EsqueleSquad group. The group published nearly 6,000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  142. resolvedcritical

    Malicious code in aeodata (PyPI)

    Malicious code was discovered in the aeodata package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  143. resolvedcritical

    Malicious code in agents-kit (PyPI)

    Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.

    PyPIAI agents & skillsCompromised package
  144. resolvedcritical

    Malicious code in adultra (PyPI)

    The adultra package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  145. resolvedhigh

    Malicious code in ai-labs-snippets-sdk (PyPI)

    The ai-labs-snippets-sdk package on PyPI contained malicious code that exfiltrates system information (IP address, username, .gitconfig) to a remote target. The malicious payload was embedded as pickle-serialized code within a file disguised as an AI model, executed during package import.

    2025 05 AI Labs Snippets SdkPyPICompromised package
  146. resolvedcritical

    Malicious code in afritonpy (PyPI)

    Malicious code was discovered in the afritonpy package on PyPI. The package contained intentional malicious functionality that could compromise systems installing it.

    PyPICompromised package
  147. resolvedhigh

    Malicious code in accesspdp (PyPI)

    The accesspdp package version 2.0.1 on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  148. resolvedcritical

    Malicious code in 3m-promo-gen-api (PyPI)

    Malicious code was discovered in the 3m-promo-gen-api package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  149. resolvedcritical

    Malicious code in 191239aa (PyPI)

    Malicious code was published in the PyPI package 191239aa. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  150. resolvedcritical

    Malicious code in 4123 (PyPI)

    Malicious code was discovered in the PyPI package 4123. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4727.

    PyPICompromised package
  151. resolvedcritical

    Malicious code in 233-misc (PyPI)

    Malicious code was discovered in the 233-misc package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  152. resolvedcritical

    Malicious code in 1923tsl1 (PyPI)

    Malicious code was discovered in the 1923tsl1 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  153. resolvedcritical

    Malicious code in 7-0 (PyPI)

    Malicious code was discovered in the PyPI package 7-0. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  154. resolvedcritical

    Malicious code in 3m-promo-link-gen (PyPI)

    Malicious code was discovered in the 3m-promo-link-gen package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4726.

    PyPICompromised package
  155. resolvedcritical

    Malicious code in 90456984689490856 (PyPI)

    Malicious code was published in the PyPI package 90456984689490856. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  156. resolvedcritical

    Malicious code in abhamzufu (PyPI)

    The PyPI package abhamzufu contained malicious code that executed during installation via a compromised setup.py install command override. The package had no legitimate purpose and was part of the 2025-10-wangzhou183 campaign.

    2025 10 Wangzhou183PyPICompromised package
  157. resolvedcritical

    Malicious code in aaiohttp (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including aaiohttp, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  158. resolvedcritical

    Malicious code in account-eth (PyPI)

    Malicious code was discovered in the account-eth package on PyPI. The package contained unauthorized code injected into one or more versions.

    PyPICompromised package
  159. resolvedcritical

    Malicious code in aaaazzzzaz (PyPI)

    The PyPI package aaaazzzzaz contained malicious code that downloads and executes a remote executable during installation. The package was part of the 2026-06-easyaillm campaign and has been identified and removed.

    2026 06 EasyaillmPyPICompromised package
  160. resolvedcritical

    Malicious code in abilityrequests (PyPI)

    Malicious code was discovered in the abilityrequests package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.

    PyPICompromised package
  161. resolvedcritical

    Malicious code in acloud-client (PyPI)

    A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.

    PyPICompromised packageMalicious commit
  162. resolvedhigh

    Malicious code in adafruit-display-text (PyPI)

    Malicious code was published in the adafruit-display-text package on PyPI. The package exfiltrates basic host information (IP address, username) and executes malicious code during installation via setup.py override.

    PyPICompromised package
  163. containedcritical

    Malicious code in acloud-clients (PyPI)

    A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.

    PyPICompromised packageMalicious commit
  164. resolvedhigh

    Malicious code in abseil-py (PyPI)

    Malicious code was published in the abseil-py package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.

    PyPICompromised package
  165. resolvedcritical

    Malicious code in acapy-agent-didx (PyPI)

    Malicious code was discovered in the acapy-agent-didx package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.

    PyPICompromised package
  166. resolvedhigh

    Malicious code in adafruit-imageload (PyPI)

    The adafruit-imageload package on PyPI contained malicious code that exfiltrated basic host information (IP address, username) during installation. The package overrode the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  167. resolvedcritical

    Malicious code in acme-widget-layout-utils (PyPI)

    The PyPI package acme-widget-layout-utils contained malicious code that executes a reverse shell on import. The package was published under a generic name despite being described internally as a 'pipeline hook probe', increasing the risk of accidental installation.

    PyPIMalicious commit
  168. resolvedcritical

    Malicious code in admask (PyPI)

    The admask package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a coordinated campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  169. resolvedcritical

    Malicious code in adhttp (PyPI)

    The adhttp package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malware executed spyware and information-stealing functionality.

    EsquelesquadPyPICompromised package
  170. resolvedcritical

    Malicious code in adm3 (PyPI)

    Malicious code was discovered in the adm3 package on PyPI. The incident was identified and documented by the OpenSSF malicious-packages project.

    PyPICompromised package
  171. resolvedcritical

    Malicious code in adgui (PyPI)

    The adgui package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  172. resolvedhigh

    Malicious code in adent-core-api (PyPI)

    The adent-core-api package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.

    PyPICompromised package
  173. resolvedcritical

    Malicious code in adhydra (PyPI)

    The adhydra package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  174. resolvedcritical

    Malicious code in adosint (PyPI)

    The adosint package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  175. resolvedcritical

    Malicious code in adproof (PyPI)

    The adproof package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  176. resolvedcritical

    Malicious code in adpyw (PyPI)

    The PyPI package adpyw contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  177. resolvedhigh

    Malicious code in adandv (PyPI)

    The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  178. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  179. resolvedcritical

    Malicious code in admcheck2 (PyPI)

    Malicious code was discovered in the admcheck2 package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  180. resolvedcritical

    Malicious code in adcontrol (PyPI)

    The adcontrol package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  181. resolvedcritical

    Malicious code in admc (PyPI)

    The admc package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems.

    EsquelesquadPyPICompromised package
  182. resolvedcritical

    Malicious code in adcpu (PyPI)

    The PyPI package adcpu contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  183. resolvedcritical

    Malicious code in adinfo (PyPI)

    The adinfo package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  184. resolvedcritical

    Malicious code in adcv (PyPI)

    The adcv package on PyPI contained malicious code as part of a campaign by the EsqueleSquad group. The group published nearly 6000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  185. resolvedcritical

    Malicious code in adpaypal (PyPI)

    The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.

    EsquelesquadPyPICompromised package
  186. resolvedcritical

    Malicious code in adminbypasser (PyPI)

    Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.

    PyPICompromised package
  187. resolvedcritical

    Malicious code in adv2099m2 (PyPI)

    Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  188. resolvedcritical

    Malicious code in adv2099m6 (PyPI)

    Malicious code was discovered in the adv2099m6 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.

    PyPICompromised package
  189. resolvedcritical

    Malicious code in ziphash (PyPI)

    The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.

    2025 11 UzipPyPICompromised package
  190. resolvedcritical

    Malicious code in adrandom (PyPI)

    The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  191. resolvedcritical

    Malicious code in adv2099m7 (PyPI)

    Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  192. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  193. resolvedcritical

    Malicious code in adstr (PyPI)

    The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  194. resolvedcritical

    Malicious code in afriton-py (PyPI)

    Malicious code was discovered in the afriton-py package on PyPI. The package contained intentionally injected malicious code that could compromise systems installing it.

    PyPICompromised package
  195. resolvedcritical

    Malicious code in agent-user-generate (PyPI)

    The PyPI package agent-user-generate contained malicious code that exfiltrated user data, downloaded and executed next-stage payloads, and installed infostealer malware (Lumma and a custom variant). The package cloned a legitimate project and hid malicious functionality within library usage.

    PyPICompromised package
  196. resolvedcritical

    Malicious code in aeodatav04 (PyPI)

    Malicious code was discovered in the aeodatav04 package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  197. resolvedcritical

    Malicious code in advm (PyPI)

    The advm package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    EsquelesquadPyPICompromised package
  198. resolvedhigh

    Malicious code in advdef01 (PyPI)

    The PyPI package advdef01 contained malicious code designed to exfiltrate system information (IP address, username) during installation. The package used a setup.py override to execute the malicious payload when installed.

    PyPICompromised packageMalicious commit
  199. resolvedcritical

    Malicious code in adurl (PyPI)

    The adurl package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  200. resolvedhigh

    Malicious code in affinequant (PyPI)

    The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  201. resolvedcritical

    Malicious code in adv2099m5 (PyPI)

    Malicious code was discovered in the adv2099m5 package on PyPI. The package contained intentional malicious functionality and has been cataloged by the OpenSSF malicious packages database.

    PyPICompromised package
  202. resolvedhigh

    Malicious code in aet-test (PyPI)

    The aet-test package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

    PyPICompromised package
  203. resolvedcritical

    Malicious code in advirtual (PyPI)

    The advirtual package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  204. resolvedcritical

    Malicious code in adv2099m3 (PyPI)

    Malicious code was discovered in the adv2099m3 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  205. resolvedcritical

    Malicious code in xolonavrylpbeb (PyPI)

    Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.

    PyPICompromised package
  206. resolvedcritical

    Malicious code in yfinane (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinane, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  207. resolvedcritical

    Malicious code in yfinnance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfinnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  208. resolvedcritical

    Malicious code in yfnance (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including yfnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  209. resolvedcritical

    Malicious code in ai-cypher (PyPI)

    The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.

    2025 12 AI CypherPyPICompromised package
  210. resolvedcritical

    Malicious code in ycodestyle (PyPI)

    Malicious code was distributed in the ycodestyle package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages infected local browsers with extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.

    PyPICompromised package
  211. resolvedcritical

    Malicious code in 1q847 (PyPI)

    The PyPI package 1q847 contained malicious code in the form of two DLL libraries, one of which was packed. Both libraries were recognized as malware with infosteal capabilities. The package was identified and cataloged as part of the OpenSSF malicious packages campaign.

    PyPICompromised package
  212. resolvedhigh

    Malicious code in xsltproc (PyPI)

    The xsltproc package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.

    PyPICompromised package
  213. resolvedcritical

    Malicious code in zsender (PyPI)

    A coordinated malicious package campaign on PyPI consisting of five interdependent packages (zsender, zscaner, pyapiepo, reqinstall, zmaker) designed to steal Telegram Desktop user data. The packages work together to locate Telegram Desktop folders, archive user data, and exfiltrate it to a remote server.

    PyPICompromised packageMalicious commit
  214. resolvedcritical

    Malicious code in zking (PyPI)

    Malicious code was discovered in the zking package on PyPI. The package contained malicious code that could compromise systems installing it.

    PyPICompromised package
  215. resolvedcritical

    Malicious code in afriton (PyPI)

    Malicious code was discovered in the afriton package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-11514.

    PyPICompromised package
  216. resolvedcritical

    Malicious code in zebo (PyPI)

    The zebo package on PyPI contained malicious code that automatically installs a keylogger and screenshot extraction tool with autostart persistence. The malicious campaign was identified and attributed to OpenSSF's malicious packages database.

    PyPICompromised package
  217. resolvedcritical

    Malicious code in 48484efej8id (PyPI)

    Malicious code was published in the PyPI package 48484efej8id. The package was identified and cataloged by the OpenSSF malicious-packages project.

    PyPICompromised package
  218. containedcritical

    Malicious code in youreallydontwantthispackage2131 (PyPI)

    Malicious package youreallydontwantthispackage2131 version 1.0.1 published to PyPI with code designed to exfiltrate GCP tokens. The OpenSSF Package Analysis project and security researcher kam193 identified the package communicating with malicious domains and executing suspicious commands.

    PyPICompromised package
  219. resolvedcritical

    Malicious code in a-oder (PyPI)

    Malicious code was published in the a-oder package on PyPI as part of the 2024-07-weaponized-golden campaign. The malware was designed for file exfiltration. The package has been identified and documented by the OpenSSF malicious-packages project.

    2024 07 Weaponized GoldenPyPICompromised package
  220. resolvedcritical

    Malicious code in ztasimb (PyPI)

    Malicious code was discovered in the ztasimb package on PyPI. The package was identified and reported by the OpenSSF malicious packages project.

    PyPICompromised package
  221. resolvedcritical

    Malicious code in zydnitro (PyPI)

    Malicious code was discovered in the zydnitro package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.

    PyPICompromised package
  222. resolvedcritical

    Malicious code in ygame (PyPI)

    Attacker distributed 900+ malicious packages via PyPI, including ygame, containing code that infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.

    PyPICompromised package
  223. resolvedcritical

    Malicious code in fflask (PyPI)

    Malicious code was published in the fflask package on PyPI. Importing the module triggers an infostealer that exfiltrates data and establishes persistence via autorun directory. The package appears to be a typosquatting attack on a legitimate Flask-related package.

    2024 12 ReqesstPyPICompromised packageTyposquatting
  224. containedcritical

    Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

    Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.

    npmPyPITyposquattingCompromised package
  225. activehigh

    Malicious PyPI packages give hackers control of Telegram bot servers

    A campaign active since November 2025 has distributed malicious PyPI packages—trojanized Pyrogram forks—targeting Python developers building Telegram bots. The compromised packages allow attackers to read arbitrary files on affected servers.

    PyPICompromised packageTyposquatting
  226. containedhigh

    New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

    Hackers compromised 19 science-focused packages on PyPI in a Shai-Hulud supply-chain attack. The trojanized packages were collectively downloaded hundreds of thousands of times and delivered malware designed to steal developer secrets.

    Shai-HuludPyPICompromised package
  227. activecritical

    The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent

    On June 8, 2026, multiple Graph ML PyPI packages were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections for analyst misdirection, and token-revocation wipers. The attack targeted the bioinformatics ecosystem with sophisticated evasion techniques.

    HadesPyPICompromised package
  228. containedcritical

    Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack

    Three malicious versions of Microsoft's durabletask Python package were published to PyPI on May 19, 2026, containing a 28 KB payload that steals credentials from cloud providers (AWS, Azure, GCP), Kubernetes, password managers, and developer tools. The attack has been attributed to the TeamPCP threat group and exhibits indicators of Eastern European cybercrime operations.

    TeamPCPPyPICompromised package
  229. resolvedhigh

    durabletask: TeamPCP's Latest PyPi Compromise

    Malicious versions of the PyPI package durabletask were published, attributed to the TeamPCP threat actor. The attack matches known TeamPCP tactics used in prior supply chain compromises.

    TeamPCPPyPICompromised package
  230. containedcritical

    TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package

    The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.

    TeamPCPPyPICompromised packageMalicious maintainer
  231. containedhigh

    lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel

    The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.

    Mini Shai HuludPyPICompromised packageMalicious maintainer
  232. containedcritical

    TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package

    On March 27, 2026, TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI. The group was identified by shared cryptographic signatures and exfiltration methods matching their earlier litellm compromise.

    TeamPCPPyPICompromised package
  233. containedcritical

    litellm: Credential Stealer Hidden in PyPI Wheel

    A critical supply chain compromise in litellm==1.82.8 on PyPI was identified on March 24, 2026. The malicious PyPI wheel contains a credential stealer hidden in a litellm_init.pth file that executes during package initialization.

    TeamPCPPyPICompromised package
  234. containedcritical

    bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys

    bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.

    PyPICompromised package