Malicious code in admcheck2 (PyPI)
Malicious code was discovered in the admcheck2 package on PyPI. The package contained malicious code that could compromise systems installing it.
- Disclosed
- Last updated
- Blast radius
- All users who installed affected versions of admcheck2 from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- admcheck2PyPI package
The admcheck2 package on PyPI was found to contain malicious code. This incident was identified and documented by the OpenSSF's malicious-packages project (MAL-2024-4733).\n\nThe malicious package was published to the Python Package Index, making it available for installation by users. Any system that installed the affected versions of admcheck2 would have been compromised.\n\nThe incident was disclosed on July 21, 2026, and has been documented in the GitHub Advisory database (GHSA-g9cc-3q89-q22h).
Indicators of compromise
- Packages
- admcheck2
Remediation
- Remove admcheck2 from affected systems immediately
- Audit systems that installed admcheck2 for signs of compromise
- Use dependency scanning tools to identify if admcheck2 was installed as a transitive dependency
- Review PyPI package installation logs to identify affected versions and installation dates
- Consider rotating credentials and secrets on systems that may have been compromised
Sources
- GitHub Advisory GHSA-g9cc-3q89-q22h · GitHub Advisory Database
Cite this entry
"Malicious code in admcheck2 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-admcheck2-pypi-w8qln5
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit