Malicious code in 7miners (PyPI)
The 7miners package on PyPI contained malicious code designed to clone legitimate libraries with modifications. The package downloads and executes arbitrary remote code via Telegram as a command-and-control channel.
- Disclosed
- Last updated
- Blast radius
- All users who installed the malicious 7miners package from PyPI
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- 7minersMalicious package on PyPI
The 7miners package published on PyPI was identified as malicious by the OpenSSF malicious-packages project. The package was a clone of legitimate libraries with malicious modifications intended to download and execute remote code.\n\nThe malicious payload installs a generic entry point that triggers malicious actions. The remote script allows executing arbitrary files through Telegram, which serves as the command-and-control (C2) channel for the attacker.\n\nThis incident was part of the 2026-03-pipipipi campaign and was classified as a typosquatting attack combined with a remote access trojan (RAT). The package was identified and documented by the OpenSSF's malicious-packages repository (MAL-2026-2670).
Indicators of compromise
- Packages
- 7miners
Remediation
- Remove the 7miners package immediately from any affected systems
- Audit systems that installed 7miners for signs of compromise or unauthorized access
- Review Telegram account activity and connections for suspicious command-and-control communications
- Monitor for execution of arbitrary remote scripts or unexpected process spawning
- Check PyPI for similar typosquatting packages targeting legitimate libraries
Sources
- GitHub Advisory GHSA-gf36-4363-p6qp · GitHub Advisory Database
Cite this entry
"Malicious code in 7miners (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-7miners-pypi-1g03k0
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting - resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in zamino (PyPI)
The PyPI package zamino was identified as malicious code—a clone of legitimate Aminoapps libraries with added credential exfiltration functionality. The package was part of the 2025-06-sorex campaign and has been cataloged by the OpenSSF malicious packages database.
2025 06 SorexPyPICompromised packageTyposquatting