Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in acloud-client (PyPI)

A multi-year malicious campaign on PyPI distributed packages (acloud-client, time-check-server, snapshot-photo) that clone legitimate cloud SDK packages and exfiltrate cloud credentials to remote servers. The campaign used obfuscation techniques, hiding malicious functionality in dependency chains.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of acloud-client and related packages in the campaign
Ecosystems
Attack vectors
Affected entities
  • acloud-clientMalicious clone of aliyun-python-sdk-core; exfiltrates cloud credentials
  • time-check-serverDependency used by acloud-client to exfiltrate credentials
  • snapshot-photoEarlier variant in same campaign (active for at least 2 years)

A coordinated malicious campaign on PyPI has been identified that distributes packages designed to steal cloud credentials. The campaign operates in two parts: packages like time-check-server and snapshot-photo contain code that communicates with remote servers, while packages like acloud-client are clones of legitimate Aliyun and AWS SDK packages that import these malicious dependencies and exfiltrate cloud credentials instead of benign data.\n\nThe campaign has been active for at least two years, with snapshot-photo containing the same credential-stealing functionality as the newer time-check-server package. The malicious code is intentionally hidden within library usage patterns to evade detection.\n\nAffected packages include acloud-client (a clone of aliyun-python-sdk-core), time-check-server, and snapshot-photo. The campaign demonstrates a sophisticated supply chain attack strategy using dependency confusion and package cloning to target cloud infrastructure credentials.\n\nThis incident was identified and documented by the OpenSSF malicious-packages project.

Indicators of compromise

Packages
  • acloud-client
  • time-check-server
  • snapshot-photo

Remediation

  • Remove acloud-client, time-check-server, and snapshot-photo packages from all environments
  • Audit all systems that installed these packages for unauthorized access or credential exfiltration
  • Rotate all cloud credentials (AWS, Aliyun) that may have been exposed
  • Review cloud account activity logs for suspicious access patterns
  • Use legitimate, verified packages: aliyun-python-sdk-core from official Aliyun sources and official AWS SDKs
  • Implement package verification and integrity checks in dependency management
  • Monitor PyPI for similar typosquatting or cloning attempts targeting cloud SDKs

Sources

  1. GitHub Advisory GHSA-3c4j-6pg3-xwf5 · GitHub Advisory Database

Cite this entry

"Malicious code in acloud-client (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-acloud-client-pypi-q5iw9h

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in acloud-clients (PyPI)

    A multi-year malicious campaign on PyPI distributes packages that clone legitimate cloud SDK libraries (acloud-clients, AWS clients) and inject code to exfiltrate cloud credentials via hidden dependencies like time-check-server and snapshot-photo.

    PyPICompromised packageMalicious commit
  2. resolvedcritical

    Malicious code in zmaker (PyPI)

    A coordinated malicious package campaign on PyPI targeted Telegram Desktop users. Five interdependent packages (zmaker, zscaner, pyapiepo, reqinstall, zsender) worked together to locate, archive, and exfiltrate Telegram user data to a remote server.

    PyPICompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in zscaner (PyPI)

    A coordinated malicious package campaign on PyPI targeting Telegram Desktop users. Five interdependent packages (zscaner, pyapiepo, reqinstall, zmaker, zsender) work together to locate, archive, and exfiltrate Telegram Desktop user data to a remote server.

    PyPICompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in aclient-sdk (PyPI)

    aclient-sdk on PyPI contains malicious code designed to exfiltrate cloud credentials. The package is a clone of the legitimate aliyun-python-sdk-core with injected code that imports a credential-stealing dependency and exfiltrates AWS/Alibaba Cloud tokens to a remote server.

    PyPICompromised packageMalicious commit