Malicious code in 7-0 (PyPI)
Malicious code was discovered in the PyPI package 7-0. The package contained intentional malicious functionality and has been flagged by the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on package adoption and malicious payload scope
- Ecosystems
- Attack vectors
- Affected entities
- 7-0PyPI package
The PyPI package 7-0 was identified as containing malicious code. This incident was documented and credited to the OpenSSF's malicious packages project, which maintains a curated database of known malicious software supply chain incidents.\n\nThe malicious package was cataloged under identifier MAL-2025-2927 in the OpenSSF's malicious packages repository. The discovery was published on July 21, 2026, via GitHub Security Advisories.\n\nUsers who installed this package should immediately remove it and audit their systems for any unauthorized activity or data exfiltration.
Indicators of compromise
- Packages
- 7-0
Remediation
- Immediately uninstall the 7-0 package from all affected systems
- Audit system logs and network traffic for suspicious activity
- Review any credentials or sensitive data that may have been exposed
- Update to a safe alternative package if 7-0 was a dependency
- Monitor for any follow-up indicators of compromise
Sources
- GitHub Advisory GHSA-8mh5-7qm9-9p38 · GitHub Advisory Database
Cite this entry
"Malicious code in 7-0 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-7-0-pypi-6yv25b
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit