Malicious code in adm3 (PyPI)
Malicious code was discovered in the adm3 package on PyPI. The incident was identified and documented by the OpenSSF malicious-packages project.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adm3 adoption and which versions were malicious
- Ecosystems
- Attack vectors
- Affected entities
- adm3PyPI package
A malicious code incident was identified in the adm3 package hosted on PyPI. The package was flagged as containing malicious code and documented in the OpenSSF's malicious-packages repository under identifier MAL-2024-4730.\n\nThe incident was published on July 21, 2026, via a GitHub Security Advisory (GHSA-vg8v-43xf-hrqw). The OpenSSF maintains a curated list of known malicious packages to help the community identify and avoid compromised dependencies.\n\nUsers of the adm3 package should immediately audit their environments and remove or update to a known-safe version if available.
Indicators of compromise
- Packages
- adm3
Remediation
- Remove or uninstall the adm3 package from affected environments
- Audit systems for any artifacts or changes introduced by adm3
- Monitor for suspicious activity on systems where adm3 was installed
- Check the OpenSSF malicious-packages repository for details on affected versions
- Use dependency scanning tools to identify adm3 in supply chains
Sources
- GitHub Advisory GHSA-vg8v-43xf-hrqw · GitHub Advisory Database
Cite this entry
"Malicious code in adm3 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-adm3-pypi-hqqqih
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit