Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in afritonpy (PyPI)

Malicious code was discovered in the afritonpy package on PyPI. The package contained intentional malicious functionality that could compromise systems installing it.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed affected versions of afritonpy from PyPI
Ecosystems
Attack vectors
Affected entities
  • afritonpyPyPI package

The afritonpy package on PyPI was found to contain malicious code. This incident was identified and documented by the OpenSSF's malicious-packages project (MAL-2024-11516).\n\nThe malicious package was published to the Python Package Index, making it available for installation by any user or automated system that did not verify package integrity. Any system that installed affected versions of afritonpy would have been compromised.\n\nThis incident was tracked and reported through GitHub's advisory system (GHSA-7fmr-rvqx-379q) and the OpenSSF's malicious packages repository, indicating the issue has been identified and documented by the security community.

Indicators of compromise

Packages
  • afritonpy

Remediation

  • Remove afritonpy from all systems and environments where it was installed
  • Audit systems that installed afritonpy for signs of compromise or malicious activity
  • Review package dependencies to ensure no other malicious packages were introduced
  • Use package verification tools and checksums when installing packages from PyPI
  • Monitor PyPI and security advisories for similar malicious package incidents

Sources

  1. GitHub Advisory GHSA-7fmr-rvqx-379q · GitHub Advisory Database

Cite this entry

"Malicious code in afritonpy (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-afritonpy-pypi-1imnqo

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in adpip (PyPI)

    The adpip package on PyPI was identified as malicious code, part of a campaign by EsqueleSquad that published nearly 6000 malicious packages across PyPI and NPM. The package executes spyware and information-stealing malware.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adstr (PyPI)

    The adstr package on PyPI contained malicious code as part of a campaign by EsqueleSquad group that published nearly 6000 malicious packages across PyPI and NPM. The malicious code executed spyware and information-stealing malware.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in adtool (PyPI)

    The adtool package on PyPI contained malicious code that executed spyware and information-stealing malware. This package was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    PyPICompromised package
  4. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package