Malicious code in adanbu (PyPI)
The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.
- Disclosed
- Last updated
- Blast radius
- Unknown; limited to users who installed the malicious package version 92.6
- Ecosystems
- Attack vectors
- Affected entities
- adanbu · 92.6
The malicious package 'adanbu' on PyPI was identified as part of a campaign (2024-11-byted-dast) distributing pentest-themed packages with malicious payloads. Upon installation or module import, the package triggered exfiltration of basic system information including hostname, path, and username to the package author.\n\nThe OpenSSF Package Analysis project confirmed the malicious nature of version 92.6, noting that the package communicated with a domain associated with malicious activity. The campaign appears to have used typosquatting and dependency-confusion tactics to distribute the malicious packages.\n\nWhile the exfiltrated data was limited in scope (basic system information), the package demonstrated clear malicious intent and posed a risk to any system where it was installed.
Indicators of compromise
- Packages
- adanbu
Remediation
- Uninstall the malicious package: pip uninstall adanbu
- Audit systems where adanbu was installed for unauthorized access or data exfiltration
- Review system logs for suspicious activity during the period the package was installed
- Check for any credentials or sensitive data that may have been exposed
- Monitor for follow-up attacks from the attacker who obtained system information
- Use package verification tools and dependency scanning to prevent similar typosquatting/dependency-confusion attacks
Sources
- GitHub Advisory GHSA-xh28-rv5p-mmgq · GitHub Advisory Database
Cite this entry
"Malicious code in adanbu (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-adanbu-pypi-1nk754
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in affinequant (PyPI)
The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in yelp-pkg (PyPI)
yelp-pkg, a malicious package on PyPI, was designed to exfiltrate sensitive data including environment variables during installation. The package overrides the install command in setup.py to execute malicious code and appears to be a typosquatting attack.
PyPICompromised packageTyposquatting