Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in aiassistcore (PyPI)

Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; packages distributed via PyPI with potential for widespread installation
Ecosystems
Attack vectors
Threat actor
Affected entities
  • aiassistcorePyPI package containing C2 configuration and malicious functionality
  • cognikitPyPI package containing C2 configuration and malicious functionality
  • aichannelPyPI package providing fake functionality while executing malicious actions from dependencies

A coordinated campaign distributing malicious Python packages via PyPI was identified, with aiassistcore, cognikit, and aichannel as confirmed malicious packages. Some packages (cognikit, aiassistcore) contain C2 configuration and malicious functionality directly, while others (aichannel) provide fake functionality while silently executing malicious actions from their dependencies.\n\nThe malicious code performs multiple harmful actions: replacing cryptocurrency wallet addresses with attacker-controlled addresses, exfiltrating browser data, establishing remote control over infected devices, and injecting malicious browser extensions. The packages also include keylogger and clipboard-monitoring capabilities.\n\nIoCs and tactics are consistent with North Korea's "Contagious Interview" campaign. The packages are believed to be used as dependencies in malicious interview assessment platforms or cryptocurrency-related projects to compromise developer and user systems.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • aiassistcore
  • cognikit
  • aichannel

Remediation

  • Immediately uninstall aiassistcore, cognikit, and aichannel from all systems
  • Audit all systems that installed these packages for signs of compromise (wallet address modifications, browser extensions, persistence mechanisms)
  • Rotate cryptocurrency wallet addresses and review transaction history for unauthorized transfers
  • Scan systems for keyloggers, clipboard monitors, and remote access tools
  • Review browser extensions and remove any suspicious or unfamiliar extensions
  • Change all credentials on affected systems, particularly for cryptocurrency wallets and sensitive accounts
  • Monitor for indicators of compromise related to the 'Contagious Interview' campaign
  • Implement dependency scanning and verification in development workflows to prevent installation of malicious packages

Sources

  1. GitHub Advisory GHSA-wwmq-cqmr-r335 · GitHub Advisory Database

Cite this entry

"Malicious code in aiassistcore (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-aiassistcore-pypi-1snh4t

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in cognikit (PyPI)

    Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in aiprepkit (PyPI)

    Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in catalogai (PyPI)

    Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in ailaunchkit (PyPI)

    A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit