Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in aclient-sdk (PyPI)

aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of aclient-sdk and related packages in the campaign
Ecosystems
Attack vectors
Affected entities
  • aclient-sdkMalicious package on PyPI that exfiltrates cloud credentials

aclient-sdk is a malicious package published to PyPI as part of a multi-year credential-theft campaign. The package is a clone of the legitimate aliyun-python-sdk-core library with intentional modifications to client.py that import a malicious dependency (time-check-server or similar) and exfiltrate cloud credentials instead of benign date information.

The campaign operates in two layers: first-stage packages (time-check-server, snapshot-photo) contain code that communicates with a remote server, and second-stage packages (aclient-sdk and variants) clone legitimate cloud SDK libraries and use the first-stage packages as dependencies to steal credentials. Similar variations target AWS clients.

Evidence indicates the campaign has been active for at least two years, with snapshot-photo containing the same credential-theft functionality as newer packages. The malicious intent is clear: credential exfiltration from cloud environments.

This incident was identified and credited to the OpenSSF malicious-packages project.

Indicators of compromise

Packages
  • aclient-sdk
  • time-check-server
  • snapshot-photo
  • alicloud-client

Remediation

  • Immediately remove aclient-sdk and related packages (time-check-server, snapshot-photo, alicloud-client variants) from all environments
  • Audit PyPI package dependencies for any use of these malicious packages
  • Rotate all cloud credentials (AWS, Alibaba Cloud) that may have been exposed through systems using these packages
  • Review cloud access logs for suspicious activity during the period these packages were installed
  • Use only official, verified cloud SDK packages from trusted sources (e.g., aliyun-python-sdk-core from Alibaba Cloud's official repository)
  • Implement package pinning and verification in dependency management to prevent installation of typosquatted or malicious variants

Sources

  1. GitHub Advisory GHSA-9r2q-63q3-w86x · GitHub Advisory Database

Cite this entry

"Malicious code in aclient-sdk (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-aclient-sdk-pypi-1wcjrf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in alphalend-layouts (PyPI)

    The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.

    PyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in aichannel (PyPI)

    Multiple malicious PyPI packages (aichannel, cognikit, aiassistcore) were published as part of a coordinated campaign attributed to North Korea's "Contagious Interview" operation. The packages contain infostealer functionality including cryptocurrency wallet address replacement, browser data exfiltration, keylogging, clipboard monitoring, and remote access capabilities.

    Contagious InterviewPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in ailaunchkit (PyPI)

    A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in aiassistcore (PyPI)

    Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit