PyPI supply chain incidents
234 confirmed incidents affecting the pypi ecosystem.
- containedhigh
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-ai-platform (PyPI)
The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.
PyPICompromised package - resolvedcritical
Malicious code in telerape (PyPI)
The telerape package on PyPI contained malicious code that placed a reverse shell in a PTH file, enabling arbitrary command execution on victim machines. The package was identified and cataloged as part of the 2026-07-telerape malicious campaign by the OpenSSF.
2026 07 TelerapePyPICompromised package - resolvedcritical
Malicious code in ml-data-shared (PyPI)
The ml-data-shared package on PyPI contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and cataloged as part of the 2026-07-ml-shared malicious campaign by the OpenSSF.
2026 07 ML SharedPyPICompromised package - resolvedcritical
Malicious code in ml-nps-shared (PyPI)
The PyPI package ml-nps-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.
2026 07 ML SharedPyPICompromised package - containedcritical
Malicious code in aichannel (PyPI)
Multiple malicious PyPI packages (aichannel, cognikit, aiassistcore) were published as part of a coordinated campaign attributed to North Korea's "Contagious Interview" operation. The packages contain infostealer functionality including cryptocurrency wallet address replacement, browser data exfiltration, keylogging, clipboard monitoring, and remote access capabilities.
Contagious InterviewPyPICompromised packageMalicious commit - containedhigh
Malicious code in ml-shared (PyPI)
The PyPI package ml-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported by the OpenSSF malicious-packages project.
2026 07 ML SharedPyPICompromised package - resolvedhigh
Malicious code in ml-fdbk-shared (PyPI)
The PyPI package ml-fdbk-shared contained malicious code that exfiltrates system information and environment variables during installation. The package was identified and reported as part of the 2026-07-ml-shared malicious campaign.
2026 07 ML SharedPyPICompromised package - containedcritical
Malicious code in ailaunchkit (PyPI)
A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiassistcore (PyPI)
Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - resolvedcritical
Malicious code in reguestsc (PyPI)
A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.
PyPITyposquattingCompromised package - resolvedhigh
Malicious code in walmart-genai-trace (PyPI)
walmart-genai-trace, a malicious package on PyPI, exfiltrates basic host information (IP, username) upon installation or import. The package overrides the install command in setup.py to execute malicious code during installation.
PyPICompromised package - containedcritical
Malicious code in catalogai (PyPI)
Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiprepkit (PyPI)
Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in cognikit (PyPI)
Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - resolvedhigh
Malicious code in phabricator-client (PyPI)
The phabricator-client package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - containedcritical
Malicious code in mcp-search-server (PyPI)
mcp-search-server on PyPI contained malicious code in versions published from July 2026 onward. The package included hidden "phone home" functionality disguised as a "share compute swarm" feature, and was part of a coordinated campaign with another malicious package designed to deploy coin miners on user machines.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in ai-perf-toolkit (PyPI)
The PyPI package ai-perf-toolkit contained malicious code that initiates cryptomining for a hardcoded wallet upon import. The malicious campaign was identified and attributed to OpenSSF's malicious-packages repository.
PyPICompromised package - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in mrmustard (PyPI)
A malicious version of the mrmustard package was published to PyPI containing code that exfiltrates SSH keys, AWS credentials, Kubernetes config, environment variables, and system identifiers to a remote endpoint. The payload includes multiple persistence mechanisms that survive package uninstallation.
PyPICompromised package - containedcritical
Malicious code in karpatkey (PyPI)
The karpatkey package on PyPI contained malicious code that exfiltrated sensitive credentials and data from infected systems. Upon import, the package spawned a background daemon thread that collected SSH keys, AWS/GCP credentials, kubeconfig, cryptocurrency wallets, and other secrets, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in cfgzen (PyPI)
Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.
2026 07 CfgzenPyPICompromised package - resolvedcritical
Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.
PyPICompromised package - resolvedcritical
Malicious code in yfinnace (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinnace, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinanec (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinanec, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in xx-ent-wiki-sm (PyPI)
The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in xwormclient (PyPI)
The xwormclient package on PyPI contained malicious code that downloads and executes a remote executable upon import. The package was identified as part of campaign 2025-08-k7eel and has been flagged by the OpenSSF malicious packages database.
2025 08 K7eelPyPICompromised package - resolvedcritical
Malicious code in yellorq (PyPI)
Malicious code was discovered in the yellorq package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing intentional malicious functionality.
PyPICompromised package - resolvedcritical
Malicious code in xuiniadb (PyPI)
Malicious code was discovered in the xuiniadb package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in yfiance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfiance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ysocks (PyPI)
Malicious code was distributed in the ysocks package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ypj (PyPI)
Malicious code was discovered in the ypj package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in ypinstaller (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ypinstaller, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ytest-cov (PyPI)
Malicious code was discovered in the ytest-cov package on PyPI. The package contained malicious payload that could compromise systems of users who installed it.
PyPICompromised package - containedcritical
Malicious code in yt-api-dlp (PyPI)
yt-api-dlp, a typosquat of the legitimate yt-dlp package on PyPI, contains malicious code that downloads encrypted payloads and communicates with a C2 server via the Polygon blockchain during import. The package was a near-verbatim copy of yt-dlp with added malicious functionality.
PyPITyposquattingCompromised package - resolvedcritical
Malicious code in youtubebot (PyPI)
Malicious code was discovered in the youtubebot package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6251.
PyPICompromised package - resolvedcritical
Malicious code in ypthon-binance (PyPI)
Over 900 malicious packages were distributed via PyPI, including ypthon-binance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in zabitog (PyPI)
Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.
PyPICompromised packageDependency confusion - resolvedcritical
Malicious code in zakuraweb (PyPI)
The zakuraweb package on PyPI contained malicious code that exfiltrates Discord tokens upon import. The package was identified as part of the 2025-11-morosint campaign and has been documented by the OpenSSF malicious packages repository.
2025 11 MorosintPyPICompromised package - resolvedcritical
Malicious code in zeubilamouche (PyPI)
Malicious code was discovered in the zeubilamouche package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in zlib1g-dev (PyPI)
Malicious code was discovered in the zlib1g-dev package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.
PyPICompromised package - resolvedhigh
Malicious code in zero123 (PyPI)
Malicious code was published in the zero123 package on PyPI as part of a pentest campaign. The package exfiltrates basic system information (hostname, path, username) to the package author upon installation or import.
PyPICompromised packageTyposquatting - containedcritical
Malicious code in zzzzthisisitwantsafecheckitzzzz (PyPI)
The PyPI package zzzzthisisitwantsafecheckitzzzz version 1.0.0 contained malicious code that downloads and executes remote backdoor trojans during installation when run under specific usernames. The OpenSSF Package Analysis project confirmed the package executes commands associated with malicious behavior.
PyPICompromised package - resolvedcritical
Malicious code in zenomenallib (PyPI)
zenomenallib, a PyPI package, contained malicious code designed to exfiltrate sensitive files. The malicious payload was embedded in different locations across variants: module import, native binaries, or setup.py scripts. The package was identified and cataloged as part of the 2025-08-xenlib campaign.
2025 08 XenlibPyPICompromised package - resolvedcritical
Malicious code in zlsrc (PyPI)
Malicious code was discovered in the zlsrc package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6626.
PyPICompromised package - resolvedcritical
Malicious code in zmaker (PyPI)
A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in 3web-py (PyPI)
The PyPI package 3web-py contained malicious code designed to function as an infostealer. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.
Funcaptcha RU CampaignPyPICompromised package - resolvedcritical
Malicious code in 3-0 (PyPI)
Malicious code was discovered in the 3-0 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 3web (PyPI)
The PyPI package 3web contained malicious code designed to steal information. The package was part of the funcaptcha-ru campaign and has been identified and cataloged by the OpenSSF malicious packages project.
Funcaptcha RUPyPICompromised package - resolvedcritical
Malicious code in 7miners (PyPI)
The 7miners package on PyPI contained malicious code designed to clone legitimate libraries with modifications. The package downloads and executes arbitrary remote code via Telegram as a command-and-control channel.
2026 03 PipipipiPyPICompromised packageTyposquatting - resolvedcritical
Malicious code in adad (PyPI)
The PyPI package 'adad' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in aclient-sdk (PyPI)
aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in a1rn (PyPI)
Malicious code was discovered in the a1rn package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4729.
PyPICompromised package - resolvedcritical
Malicious code in a3s-code (PyPI)
The a3s-code PyPI package contained malicious code that fetched and executed native binaries (.so/.pyd/.dylib) from a GitHub organization (A3S-Lab) distinct from the documented project (AI45Lab), bypassing pip build isolation and hash verification.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in acpi-tables (PyPI)
The acpi-tables package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - resolvedhigh
Malicious code in adanbu (PyPI)
The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in acloud-client-uses (PyPI)
A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.
PyPICompromised packageTyposquatting - resolvedcritical
Malicious code in adgame (PyPI)
The adgame package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adload (PyPI)
The adload package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adgrand (PyPI)
The adgrand package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpost (PyPI)
The adpost package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adm4 (PyPI)
Malicious code was discovered in the adm4 package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adcandy (PyPI)
The adcandy package on PyPI contained malicious code designed to execute spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - containedcritical
Malicious code in zakuchienne (PyPI)
The PyPI package zakuchienne contains malicious code that functions as an infostealer, exfiltrating credentials, browser data, and files. The malware includes sandbox detection capabilities and was identified as part of the 2025-11-mescouilles campaign.
2025 11 MescouillesPyPICompromised package - resolvedcritical
Malicious code in adcraft (PyPI)
The adcraft package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in admine (PyPI)
The PyPI package 'admine' contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in admcheck (PyPI)
Malicious code was discovered in multiple versions of the admcheck package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m (PyPI)
Malicious code was discovered in the adv2099m package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4734.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m4 (PyPI)
Malicious code was discovered in the adv2099m4 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adtool (PyPI)
The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpip (PyPI)
The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adsplit (PyPI)
The adsplit package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in xorg-renderproto (PyPI)
Malicious code was discovered in the xorg-renderproto package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolofyxkotqwko (PyPI)
Malicious code was discovered in the PyPI package xolofyxkotqwko. The package was identified and reported by the OpenSSF malicious-packages project.
PyPICompromised package - containedcritical
Malicious code in xxx-bale (PyPI)
The PyPI package xxx-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload requires a separate trigger to activate.
2025 07 Cas Base CampaignPyPICompromised package - resolvedhigh
Malicious code in yeshsurya (PyPI)
The yeshsurya package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in yelp-cgeom1 (PyPI)
The PyPI package yelp-cgeom1 version 0.1 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedcritical
Malicious code in yffinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yffinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in xoloxwmellxliq (PyPI)
Malicious code was discovered in the xoloxwmellxliq package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6248.
PyPICompromised package - resolvedcritical
Malicious code in xologrekjlqzxj (PyPI)
Malicious code was discovered in the xologrekjlqzxj package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in xoloqmotdjpbic (PyPI)
Malicious code was discovered in the xoloqmotdjpbic package on PyPI. The package was identified and reported by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in zipf (PyPI)
Malicious code was discovered in the zipf package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in znomig (PyPI)
Malicious code was discovered in the znomig package on PyPI. The package contained intentional malicious functionality and was cataloged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in zyqnuutupjerllnbxaeq (PyPI)
Malicious code was published in the zyqnuutupjerllnbxaeq package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolosamsdyhcfa (PyPI)
Malicious code was discovered in the xolosamsdyhcfa package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in yfinancce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinancce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malicious code in xyq-drama-skill (PyPI)
xyq-drama-skill, a PyPI package, contained malicious code that downloads and executes an unsigned binary from a remote server during installation and on command invocation. The package masquerades as a Chinese short-video drama script generator but actually deploys what appears to be a COFFLoader beacon.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in yfinnce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinnce, which infected local browsers with a malicious extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in yellyproxies (PyPI)
Malicious code was discovered in the yellyproxies package on PyPI. The package contained malicious functionality that could compromise systems of users who installed it.
PyPICompromised package - resolvedcritical
Malicious code in yfiinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfiinance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in yfinacne (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinacne, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - containedhigh
Malicious code in yhaplo1 (PyPI)
Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.
PyPIDependency confusionCompromised package - resolvedcritical
Malicious code in yfinannce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinannce, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malicious code in yeahmankema (PyPI)
Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.
2026 05 CrayrandomizPyPICompromised package - resolvedcritical
Malicious code in yfiannce (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfiannce, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinaance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinaance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yc-as-client (PyPI)
The PyPI package yc-as-client version 11.11.3 was identified as malicious by the OpenSSF Package Analysis project. The malicious code communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedcritical
Malicious code in xxoo-bale (PyPI)
The PyPI package xxoo-bale contained malicious code designed to download and execute remotely stored malware with persistence mechanisms. The malicious payload required a separate trigger to activate.
2025 07 Cas BasePyPICompromised package - resolvedcritical
Malicious code in xxlsxwriter (PyPI)
Malicious code was distributed in the xxlsxwriter package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious versions installed browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedhigh
Malicious code in yc-depconf-test-807dff (PyPI)
The PyPI package yc-depconf-test-807dff contains malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - resolvedcritical
Malicious code in yfinace (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinace, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinancee (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinancee, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in ytorch (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ytorch, designed to infect local browsers with malicious extensions. The malicious extension manipulates clipboard content and replaces cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets.
PyPICompromised package - containedcritical
Malicious code in yolov8mini (PyPI)
The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in ython-binance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ython-binance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised packageTyposquatting - resolvedcritical
Malicious code in yvper (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yvper, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yyfinance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yyfinance, which infected local browsers with a malicious extension designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - containedcritical
Malicious code in yuzo (PyPI)
The yuzo package on PyPI contained malicious code implementing an infostealer (CStealer-based) designed to exfiltrate browser data and other sensitive information to a hardcoded Discord webhook. Multiple versions of the package were affected with varying implementations of the malware.
2025 09 SuyoPyPICompromised package - resolvedcritical
Malicious code in yfniance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfniance, which installed malicious browser extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in youtube-new (PyPI)
Malicious code was discovered in the youtube-new package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41801.
PyPICompromised package - resolvedcritical
Malicious code in youreallydontwantthispackage2132 (PyPI)
Malicious code was published in the PyPI package youreallydontwantthispackage2132 version 1.0.3. The package executes malicious code during installation via setup.py override and communicates with domains associated with malicious activity, exfiltrating environment variables and other data.
PyPICompromised packageTyposquatting - resolvedcritical
Malicious code in ypcodestyle (PyPI)
Malicious code was distributed in the ypcodestyle package on PyPI as part of a campaign distributing 900+ compromised packages. The malware installs a malicious browser extension designed to manipulate the clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yzip (PyPI)
The yzip package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and infosteal capabilities, tracked as campaign 2025-11-uzip.
2025 11 UzipPyPICompromised package - resolvedcritical
Malicious code in zafira (PyPI)
Malicious code was discovered in the zafira package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6252.
PyPICompromised package - resolvedcritical
Malicious code in ypsocks (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ypsocks, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedhigh
Malicious code in your-module-name (PyPI)
The your-module-name package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in yper (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yper, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses. The campaign was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedhigh
Malicious code in yt-yson-bindings (PyPI)
The yt-yson-bindings package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in ziggonext (PyPI)
Malicious code was discovered in the ziggonext package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-6623.
PyPICompromised package - resolvedcritical
Malicious code in zamino (PyPI)
The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.
2025 06 SorexPyPICompromised packageTyposquatting - resolvedcritical
Malicious code in zlapp (PyPI)
Malicious code was discovered in the zlapp package on PyPI. The package contained intentional malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - activecritical
Malicious code in zhopaorlaaato (PyPI)
The PyPI package zhopaorlaaato contains malicious code that runs an infostealer targeting Telegram and Discord credentials. Depending on version, the infostealer is either embedded in the package or downloaded from a remote URL for execution.
PyPICompromised package - resolvedcritical
Malicious code in zatta (PyPI)
Malicious code was discovered in the zatta package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6253.
PyPICompromised package - resolvedhigh
Malicious code in zip-me (PyPI)
The PyPI package zip-me contained malicious code designed to exfiltrate system information including IP address and username. The malware was activated during package installation via a metaclass override in setup.py and employed VM-detection techniques to avoid analysis.
2024 12 Langer UpdaterPyPICompromised package - resolvedcritical
Malicious code in zefkopzekfo (PyPI)
Malicious code was discovered in the zefkopzekfo package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6254.
PyPICompromised package - resolvedcritical
Malicious code in zhpt1cscoe (PyPI)
Malicious code was discovered in the zhpt1cscoe package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-6257.
PyPICompromised package - resolvedcritical
Malicious code in zelixnitro (PyPI)
Malicious code was discovered in the zelixnitro package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in ziugxfbvo (PyPI)
The PyPI package ziugxfbvo contained malicious code that executed automatically on import, functioning as an infostealer and remote access trojan (RAT) with capabilities including command execution, file exfiltration, screen recording, and GUI automation.
2026 04 Process SupportPyPICompromised package - resolvedcritical
Malicious code in zproxy2 (PyPI)
Malicious code was discovered in the zproxy2 package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in zscaner (PyPI)
A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in zorosnitro (PyPI)
Malicious code was discovered in the zorosnitro package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in zlibxjson (PyPI)
Malicious code was published in the zlibxjson package on PyPI as part of the zlibxjson-discord-cookies campaign. The package contained infostealer functionality designed to steal Discord cookies and other sensitive data from infected systems.
Zlibxjson Discord CookiesPyPICompromised package - resolvedcritical
Malicious code in zproxy (PyPI)
Malicious code was discovered in the zproxy package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adpull (PyPI)
The adpull package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adram (PyPI)
The PyPI package adram contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpep (PyPI)
The adpep package on PyPI contained malicious code as part of a campaign by EsqueleSquad group. The group published nearly 6,000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in aeodata (PyPI)
Malicious code was discovered in the aeodata package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in agents-kit (PyPI)
Malicious code was discovered in the agents-kit package on PyPI. The package was flagged by the OpenSSF malicious packages database as containing malicious code.
PyPIAI agents & skillsCompromised package - resolvedcritical
Malicious code in adultra (PyPI)
The adultra package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in ai-labs-snippets-sdk (PyPI)
The ai-labs-snippets-sdk package on PyPI contained malicious code that exfiltrates system information (IP address, username, .gitconfig) to a remote target. The malicious payload was embedded as pickle-serialized code within a file disguised as an AI model, executed during package import.
2025 05 AI Labs Snippets SdkPyPICompromised package - resolvedcritical
Malicious code in afritonpy (PyPI)
Malicious code was discovered in the afritonpy package on PyPI. The package contained intentional malicious functionality that could compromise systems installing it.
PyPICompromised package - resolvedhigh
Malicious code in accesspdp (PyPI)
The accesspdp package version 2.0.1 on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in 3m-promo-gen-api (PyPI)
Malicious code was discovered in the 3m-promo-gen-api package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 191239aa (PyPI)
Malicious code was published in the PyPI package 191239aa. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in 4123 (PyPI)
Malicious code was discovered in the PyPI package 4123. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4727.
PyPICompromised package - resolvedcritical
Malicious code in 233-misc (PyPI)
Malicious code was discovered in the 233-misc package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in 1923tsl1 (PyPI)
Malicious code was discovered in the 1923tsl1 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in 7-0 (PyPI)
Malicious code was discovered in the PyPI package 7-0. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 3m-promo-link-gen (PyPI)
Malicious code was discovered in the 3m-promo-link-gen package on PyPI. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4726.
PyPICompromised package - resolvedcritical
Malicious code in 90456984689490856 (PyPI)
Malicious code was published in the PyPI package 90456984689490856. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in abhamzufu (PyPI)
The PyPI package abhamzufu contained malicious code that executed during installation via a compromised setup.py install command override. The package had no legitimate purpose and was part of the 2025-10-wangzhou183 campaign.
2025 10 Wangzhou183PyPICompromised package - resolvedcritical
Malicious code in aaiohttp (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including aaiohttp, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in account-eth (PyPI)
Malicious code was discovered in the account-eth package on PyPI. The package contained unauthorized code injected into one or more versions.
PyPICompromised package - resolvedcritical
Malicious code in aaaazzzzaz (PyPI)
The PyPI package aaaazzzzaz contained malicious code that downloads and executes a remote executable during installation. The package was part of the 2026-06-easyaillm campaign and has been identified and removed.
2026 06 EasyaillmPyPICompromised package - resolvedcritical
Malicious code in abilityrequests (PyPI)
Malicious code was discovered in the abilityrequests package on PyPI. The package was identified by the OpenSSF malicious-packages project as containing malicious code.
PyPICompromised package - resolvedcritical
Malicious code in acloud-client (PyPI)
A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.
PyPICompromised packageMalicious commit - resolvedhigh
Malicious code in adafruit-display-text (PyPI)
Malicious code was published in the adafruit-display-text package on PyPI. The package exfiltrates basic host information (IP address, username) and executes malicious code during installation via setup.py override.
PyPICompromised package - containedcritical
Malicious code in acloud-clients (PyPI)
A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.
PyPICompromised packageMalicious commit - resolvedhigh
Malicious code in abseil-py (PyPI)
Malicious code was published in the abseil-py package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.
PyPICompromised package - resolvedcritical
Malicious code in acapy-agent-didx (PyPI)
Malicious code was discovered in the acapy-agent-didx package on PyPI. The package was identified by the OpenSSF malicious packages project as containing malicious code.
PyPICompromised package - resolvedhigh
Malicious code in adafruit-imageload (PyPI)
The adafruit-imageload package on PyPI contained malicious code that exfiltrated basic host information (IP address, username) during installation. The package overrode the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in acme-widget-layout-utils (PyPI)
The PyPI package acme-widget-layout-utils contained malicious code that executes a reverse shell on import. The package was published under a generic name despite being described internally as a 'pipeline hook probe', increasing the risk of accidental installation.
PyPIMalicious commit - resolvedcritical
Malicious code in admask (PyPI)
The admask package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a coordinated campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adhttp (PyPI)
The adhttp package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malware executed spyware and information-stealing functionality.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adm3 (PyPI)
Malicious code was discovered in the adm3 package on PyPI. The incident was identified and documented by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adgui (PyPI)
The adgui package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in adent-core-api (PyPI)
The adent-core-api package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - resolvedcritical
Malicious code in adhydra (PyPI)
The adhydra package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adosint (PyPI)
The adosint package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adproof (PyPI)
The adproof package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpyw (PyPI)
The PyPI package adpyw contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in admcheck2 (PyPI)
Malicious code was discovered in the admcheck2 package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in adcontrol (PyPI)
The adcontrol package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in admc (PyPI)
The admc package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM ecosystems.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adcpu (PyPI)
The PyPI package adcpu contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adinfo (PyPI)
The adinfo package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The package executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adcv (PyPI)
The adcv package on PyPI contained malicious code as part of a campaign by the EsqueleSquad group. The group published nearly 6000 malicious PyPI and NPM packages designed to execute spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adpaypal (PyPI)
The adpaypal package on PyPI contained malicious code executing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious PyPI and NPM packages.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adminbypasser (PyPI)
Malicious code was published in the adminbypasser package on PyPI. The package silently downloads and executes remote code, establishing persistence via autostart mechanisms. The remote domain used by the malware no longer exists at the time of analysis.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m2 (PyPI)
Malicious code was discovered in the adv2099m2 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m6 (PyPI)
Malicious code was discovered in the adv2099m6 package on PyPI. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in ziphash (PyPI)
The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.
2025 11 UzipPyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adstr (PyPI)
The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in afriton-py (PyPI)
Malicious code was discovered in the afriton-py package on PyPI. The package contained intentionally injected malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in agent-user-generate (PyPI)
The PyPI package agent-user-generate contained malicious code that exfiltrated user data, downloaded and executed next-stage payloads, and installed infostealer malware (Lumma and a custom variant). The package cloned a legitimate project and hid malicious functionality within library usage.
PyPICompromised package - resolvedcritical
Malicious code in aeodatav04 (PyPI)
Malicious code was discovered in the aeodatav04 package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in advm (PyPI)
The advm package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in advdef01 (PyPI)
The PyPI package advdef01 contained malicious code designed to exfiltrate system information (IP address, username) during installation. The package used a setup.py override to execute the malicious payload when installed.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in adurl (PyPI)
The adurl package on PyPI was identified as malicious, containing spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedhigh
Malicious code in affinequant (PyPI)
The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in adv2099m5 (PyPI)
Malicious code was discovered in the adv2099m5 package on PyPI. The package contained intentional malicious functionality and has been cataloged by the OpenSSF malicious packages database.
PyPICompromised package - resolvedhigh
Malicious code in aet-test (PyPI)
The aet-test package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedcritical
Malicious code in advirtual (PyPI)
The advirtual package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in adv2099m3 (PyPI)
Malicious code was discovered in the adv2099m3 package on PyPI. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolonavrylpbeb (PyPI)
Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.
PyPICompromised package - resolvedcritical
Malicious code in yfinane (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinane, which infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfinnance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfinnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in yfnance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ai-cypher (PyPI)
The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.
2025 12 AI CypherPyPICompromised package - resolvedcritical
Malicious code in ycodestyle (PyPI)
Malicious code was distributed in the ycodestyle package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages infected local browsers with extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in 1q847 (PyPI)
The PyPI package 1q847 contained malicious code in the form of two DLL libraries, one of which was packed. Both libraries were recognized as malware with infosteal capabilities. The package was identified and cataloged as part of the OpenSSF malicious packages campaign.
PyPICompromised package - resolvedhigh
Malicious code in xsltproc (PyPI)
The xsltproc package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - resolvedcritical
Malicious code in zsender (PyPI)
A coordinated malicious package campaign on PyPI consisting of five interdependent packages (zsender, zscaner, pyapiepo, reqinstall, zmaker) designed to steal Telegram Desktop user data. The packages work together to locate Telegram Desktop folders, archive user data, and exfiltrate it to a remote server.
PyPICompromised packageMalicious commit - resolvedcritical
Malicious code in zking (PyPI)
Malicious code was discovered in the zking package on PyPI. The package contained malicious code that could compromise systems installing it.
PyPICompromised package - resolvedcritical
Malicious code in afriton (PyPI)
Malicious code was discovered in the afriton package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-11514.
PyPICompromised package - resolvedcritical
Malicious code in zebo (PyPI)
The zebo package on PyPI contained malicious code that automatically installs a keylogger and screenshot extraction tool with autostart persistence. The malicious campaign was identified and attributed to OpenSSF's malicious packages database.
PyPICompromised package - resolvedcritical
Malicious code in 48484efej8id (PyPI)
Malicious code was published in the PyPI package 48484efej8id. The package was identified and cataloged by the OpenSSF malicious-packages project.
PyPICompromised package - containedcritical
Malicious code in youreallydontwantthispackage2131 (PyPI)
Malicious package youreallydontwantthispackage2131 version 1.0.1 published to PyPI with code designed to exfiltrate GCP tokens. The OpenSSF Package Analysis project and security researcher kam193 identified the package communicating with malicious domains and executing suspicious commands.
PyPICompromised package - resolvedcritical
Malicious code in a-oder (PyPI)
Malicious code was published in the a-oder package on PyPI as part of the 2024-07-weaponized-golden campaign. The malware was designed for file exfiltration. The package has been identified and documented by the OpenSSF malicious-packages project.
2024 07 Weaponized GoldenPyPICompromised package - resolvedcritical
Malicious code in ztasimb (PyPI)
Malicious code was discovered in the ztasimb package on PyPI. The package was identified and reported by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in zydnitro (PyPI)
Malicious code was discovered in the zydnitro package on PyPI. The package contained malicious functionality and was identified by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in ygame (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including ygame, containing code that infected local browsers with malicious extensions designed to manipulate clipboard and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in fflask (PyPI)
Malicious code was published in the fflask package on PyPI. Importing the module triggers an infostealer that exfiltrates data and establishes persistence via autorun directory. The package appears to be a typosquatting attack on a legitimate Flask-related package.
2024 12 ReqesstPyPICompromised packageTyposquatting - containedcritical
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Malicious packages impersonating Paysafe, Skrill, and Neteller SDKs were published on npm and PyPI, delivering stealer malware designed to harvest credentials from developers and application users.
npmPyPITyposquattingCompromised package - activehigh
Malicious PyPI packages give hackers control of Telegram bot servers
A campaign active since November 2025 has distributed malicious PyPI packages—trojanized Pyrogram forks—targeting Python developers building Telegram bots. The compromised packages allow attackers to read arbitrary files on affected servers.
PyPICompromised packageTyposquatting - containedhigh
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
Hackers compromised 19 science-focused packages on PyPI in a Shai-Hulud supply-chain attack. The trojanized packages were collectively downloaded hundreds of thousands of times and delivered malware designed to steal developer secrets.
Shai-HuludPyPICompromised package - activecritical
The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper Deterrent
On June 8, 2026, multiple Graph ML PyPI packages were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections for analyst misdirection, and token-revocation wipers. The attack targeted the bioinformatics ecosystem with sophisticated evasion techniques.
HadesPyPICompromised package - containedcritical
Microsoft's durabletask PyPI Package Compromised in Supply Chain Attack
Three malicious versions of Microsoft's durabletask Python package were published to PyPI on May 19, 2026, containing a 28 KB payload that steals credentials from cloud providers (AWS, Azure, GCP), Kubernetes, password managers, and developer tools. The attack has been attributed to the TeamPCP threat group and exhibits indicators of Eastern European cybercrime operations.
TeamPCPPyPICompromised package - resolvedhigh
durabletask: TeamPCP's Latest PyPi Compromise
Malicious versions of the PyPI package durabletask were published, attributed to the TeamPCP threat actor. The attack matches known TeamPCP tactics used in prior supply chain compromises.
TeamPCPPyPICompromised package - containedcritical
TeamPCP Injects Two-Stage Credential Stealer into xinference PyPI Package
The xinference package on PyPI was compromised with a two-stage credential stealer attributed to the TeamPCP threat actor. The malicious code was injected into the package, potentially affecting users who installed compromised versions.
TeamPCPPyPICompromised packageMalicious maintainer - containedhigh
lightning: Obfuscated JavaScript Credential Stealer Bundled in PyPI Wheel
The lightning PyPI package versions 2.6.2 and 2.6.3 were compromised on April 30, 2026, containing obfuscated JavaScript code designed to steal credentials. The project's GitHub account showed signs of compromise, with suspicious responses closing vulnerability reports.
Mini Shai HuludPyPICompromised packageMalicious maintainer - containedcritical
TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package
On March 27, 2026, TeamPCP injected a WAV steganography-based credential stealer into two releases of the telnyx Python SDK on PyPI. The group was identified by shared cryptographic signatures and exfiltration methods matching their earlier litellm compromise.
TeamPCPPyPICompromised package - containedcritical
litellm: Credential Stealer Hidden in PyPI Wheel
A critical supply chain compromise in litellm==1.82.8 on PyPI was identified on March 24, 2026. The malicious PyPI wheel contains a credential stealer hidden in a litellm_init.pth file that executes during package initialization.
TeamPCPPyPICompromised package - containedcritical
bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys
bittensor-wallet 4.0.2 was published to PyPI on March 17, 2026 with a backdoor that exfiltrates private keys. The compromised package remained available for approximately 48 hours before being yanked from the repository.
PyPICompromised package