Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in 90456984689490856 (PyPI)

Malicious code was published in the PyPI package 90456984689490856. The package was identified and cataloged by the OpenSSF malicious-packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on download volume and deployment scope of the malicious package.
Ecosystems
Attack vectors
Affected entities
  • 90456984689490856PyPI package

A PyPI package named 90456984689490856 was found to contain malicious code. The package was identified and documented by the OpenSSF's malicious-packages project (MAL-2024-4728).\n\nThe incident was disclosed on 2026-07-21 via a GitHub Security Advisory (GHSA-pmxj-chvc-f6p2). The malicious package was hosted on PyPI and available for installation via pip.\n\nNo specific technical details about the malicious payload are provided in the source material, but the OpenSSF classification indicates this was a confirmed malicious package incident.

Indicators of compromise

Packages
  • 90456984689490856

Remediation

  • Remove or uninstall the 90456984689490856 package from all systems where it was installed
  • Review system logs and process execution history for any suspicious activity following installation of this package
  • Check for any unauthorized modifications or data exfiltration on affected systems
  • Monitor PyPI and security advisories for related malicious packages
  • Consider implementing package verification and scanning in your dependency management workflow

Sources

  1. GitHub Advisory GHSA-pmxj-chvc-f6p2 · GitHub Advisory Database

Cite this entry

"Malicious code in 90456984689490856 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-90456984689490856-pypi-1jpevd

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in vtranalytic (PyPI)

    The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.

    PyPICompromised packageMalicious maintainer
  2. containedcritical

    Malicious code in govapkg (PyPI)

    govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in dev-helper-bg (PyPI)

    The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.

    2026 07 Make HelperPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in karpatkit (PyPI)

    The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.

    PyPICompromised packageMalicious commit