Malicious code in 48484efej8id (PyPI)
Malicious code was published in the PyPI package 48484efej8id. The package was identified and cataloged by the OpenSSF malicious-packages project.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of the malicious package version(s)
- Ecosystems
- Attack vectors
- Affected entities
- 48484efej8idPyPI package
A PyPI package named 48484efej8id was found to contain malicious code. The package was identified and documented by the OpenSSF's malicious-packages project, which maintains a catalog of known malicious software supply chain incidents.\n\nThe incident was disclosed on 2026-07-21 via a GitHub Security Advisory (GHSA-xc7g-xc25-jj3r). The malicious package was tracked under OpenSSF identifier MAL-2024-11512.\n\nNo specific technical details about the malicious payload or affected versions are provided in the source material.
Indicators of compromise
- Packages
- 48484efej8id
Remediation
- Remove the 48484efej8id package from any environments where it was installed
- Audit systems that may have executed code from this package for signs of compromise
- Review dependency trees to identify any projects that may have included this package as a transitive dependency
- Monitor for any indicators of compromise if the package was executed in production environments
Sources
- GitHub Advisory GHSA-xc7g-xc25-jj3r · GitHub Advisory Database
Cite this entry
"Malicious code in 48484efej8id (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed November 1, 2024; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-48484efej8id-pypi-16tydz
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit