Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

Malicious code in adandv (PyPI)

The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Users who installed the adandv package from PyPI
Ecosystems
Attack vectors
Affected entities
  • adandv · 912.6PyPI package

The adandv package published on PyPI was identified as malicious by both the kam193 security researcher and the OpenSSF Package Analysis project. The package contained code that triggered upon installation or module import to collect and report basic system information including hostname, path, and username to the package author.

The malicious package was part of a larger campaign (2024-11-byted-dast) involving multiple pentest-themed packages flooding PyPI. The package employed typosquatting and dependency-confusion tactics to increase installation likelihood. While the data exfiltration was limited in scope, the malicious intent was clear.

The OpenSSF Package Analysis project confirmed the malicious nature by identifying that the package communicated with domains associated with malicious activity. Version 912.6 of adandv was specifically flagged as malicious.

Indicators of compromise

Packages
  • adandv

Remediation

  • Remove the adandv package from any systems where it was installed
  • Audit systems that may have installed adandv for unauthorized access or data exfiltration
  • Review PyPI package dependencies to identify and remove any other packages from the 2024-11-byted-dast campaign
  • Monitor for suspicious outbound connections to domains associated with the malicious package
  • Use dependency scanning tools to detect similar malicious packages in supply chains

Sources

  1. GitHub Advisory GHSA-264w-47c9-634w · GitHub Advisory Database

Cite this entry

"Malicious code in adandv (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-adandv-pypi-3a3get

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  2. resolvedhigh

    Malicious code in adanbu (PyPI)

    The PyPI package 'adanbu' version 92.6 contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages on PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  3. resolvedhigh

    Malicious code in affinequant (PyPI)

    The affinequant package on PyPI contained malicious code that exfiltrated basic system information (hostname, path, username) to the package author upon installation or import. The package was part of a broader campaign of malicious packages on PyPI and communicated with a domain associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  4. resolvedcritical

    Malicious code in acloud-client-uses (PyPI)

    A malicious PyPI package named acloud-client-uses was discovered as part of a multi-year campaign that clones legitimate cloud SDK packages and exfiltrates credentials. The package imports a helper module (time-check-server) that sends cloud credentials to a remote server instead of benign data.

    PyPICompromised packageTyposquatting