Malicious code in adpyw (PyPI)
The PyPI package adpyw contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious PyPI and NPM packages. The malicious code executed spyware and information-stealing malware.
- Disclosed
- Last updated
- Blast radius
- Unknown; part of large-scale malicious package campaign
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- adpywPyPI package containing malicious code
The PyPI package adpyw was identified as containing malicious code. This package was part of a large-scale campaign by the EsqueleSquad group, which published nearly 6000 malicious packages across PyPI and NPM ecosystems.\n\nThe malicious code in adpyw was designed to execute spyware and information-stealing malware on affected systems. The incident was documented and tracked by the OpenSSF's malicious-packages repository (MAL-2023-2499).\n\nThe package has been identified and cataloged as part of coordinated malicious package distribution efforts targeting Python and JavaScript ecosystems.
Indicators of compromise
- Packages
- adpyw
Remediation
- Remove adpyw from all environments and dependencies
- Audit systems that may have installed adpyw for signs of compromise
- Review and revoke any credentials or sensitive data that may have been exposed
- Monitor for indicators of spyware or information-stealing malware activity
- Update dependency management tools to block installation of known malicious packages
Sources
- GitHub Advisory GHSA-5jhg-3335-c369 · GitHub Advisory Database
Cite this entry
"Malicious code in adpyw (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-adpyw-pypi-hsjt0s
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in vtranalytic (PyPI)
The vtranalytic package on PyPI contained malicious code implementing a Telegram-bot-driven remote administration tool that provides full system control to an attacker holding the configured bot token. The package exfiltrates credentials, SSH keys, and arbitrary files via Telegram API, and executes arbitrary shell commands through a documented `run` command.
PyPICompromised packageMalicious maintainer - containedcritical
Malicious code in govapkg (PyPI)
govapkg, a malicious PyPI package, downloads and executes a hidden binary on first use, establishing persistence via a systemd desktop autostart entry. The package obfuscates its malicious behavior through base64-encoded URLs and downloads from unverified external sources.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in dev-helper-bg (PyPI)
The PyPI package dev-helper-bg contained malicious code that executed arbitrary commands on import. The package decrypted and executed remotely-controlled code fetched from an external endpoint, and spawned a Telegram bot for command and control.
2026 07 Make HelperPyPICompromised packageMalicious commit - containedcritical
Malicious code in karpatkit (PyPI)
The karpatkit package on PyPI contained malicious code that exfiltrated sensitive credentials and secrets on import. The package spawned a daemon thread collecting environment variables, cloud credentials, SSH keys, Kubernetes tokens, cryptocurrency wallets, and shell histories, then transmitted them via HTTP to hardcoded IP addresses.
PyPICompromised packageMalicious commit