Malicious code in 1q847 (PyPI)
The PyPI package 1q847 contained malicious code in the form of two DLL libraries, one of which was packed. Both libraries were recognized as malware with infosteal capabilities. The package was identified and cataloged as part of the OpenSSF malicious packages campaign.
- Disclosed
- Last updated
- Blast radius
- All users who installed the malicious 1q847 package from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- 1q847PyPI package containing malicious DLL libraries
The PyPI package 1q847 was found to contain malicious code consisting of two DLL libraries, one of which was packed. Both libraries were widely recognized as malware by security tools.
The exact behavior of the malware is not fully documented in the advisory, but the campaign classification indicates malicious intent consistent with infostealer functionality. The package was identified by kam193 and credited to the OpenSSF malicious packages project.
The incident was cataloged under campaign 2026-01-old-1q847 with reference MAL-2026-443. The package has been flagged and removed from PyPI distribution.
Indicators of compromise
- Packages
- 1q847
Remediation
- Remove the 1q847 package from any systems where it was installed
- Scan affected systems for malware using updated antivirus/EDR tools
- Review system logs for suspicious activity from the time of installation
- Change any credentials or sensitive data that may have been exposed
- Monitor for signs of data exfiltration or unauthorized access
Sources
- GitHub Advisory GHSA-x725-7m9f-xg42 · GitHub Advisory Database
Cite this entry
"Malicious code in 1q847 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed January 1, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-1q847-pypi-13z1vr
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in riakcs (PyPI)
The riakcs package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package