Malicious code in adandu (PyPI)
The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.
- Disclosed
- Last updated
- Blast radius
- Unknown; limited to users who installed the malicious package version(s).
- Ecosystems
- Attack vectors
- Affected entities
- adanduPyPI package containing malicious code
The PyPI package 'adandu' was identified as malicious by both the kam193 security researcher and the OpenSSF Package Analysis project. The package contained code designed to exfiltrate basic system information including hostname, path, and username to the package author upon installation or module import.\n\nThe malicious package was part of a broader campaign (2024-11-byted-dast) distributing pentest-themed packages on PyPI. According to the analysis, the package employed typosquatting and dependency-confusion tactics. While the exfiltration capability was limited in scope, the package also communicated with domains associated with malicious activity.\n\nThe OpenSSF Package Analysis project formally identified the package as malicious (MAL-2024-10579) and it has been cataloged in the malicious-packages repository. The incident appears to have been detected and documented, with the malicious package now flagged in public security databases.
Indicators of compromise
- Packages
- adandu
Remediation
- Remove the 'adandu' package from any affected systems immediately
- Audit system logs for any suspicious activity or data exfiltration from the time of installation
- Review environment variables and system information that may have been exposed (hostname, username, paths)
- Check for any other packages from the same malicious campaign (2024-11-byted-dast) that may have been installed
- Use dependency scanning tools to detect and prevent installation of known malicious packages from the OpenSSF malicious-packages database
Sources
- GitHub Advisory GHSA-7mp5-4486-4wgp · GitHub Advisory Database
Cite this entry
"Malicious code in adandu (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-adandu-pypi-1ymmlw
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in adandv (PyPI)
The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in adanbu (PyPI)
The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.
PyPICompromised packageTyposquattingDependency confusion - resolvedhigh
Malicious code in affinequant (PyPI)
The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.
PyPICompromised packageTyposquattingDependency confusion - resolvedcritical
Malicious code in acloud-client-uses (PyPI)
A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.
PyPICompromised packageTyposquatting