Malicious code in aichannel (PyPI)
Multiple malicious PyPI packages (aichannel, cognikit, aiassistcore) were published as part of a coordinated campaign attributed to North Korea's "Contagious Interview" operation. The packages contain infostealer functionality including cryptocurrency wallet address replacement, browser data exfiltration, keylogging, clipboard monitoring, and remote access capabilities.
- Disclosed
- Last updated
- Blast radius
- Multiple PyPI packages used as dependencies in interview assessments and cryptocurrency projects; potential impact on end-user devices including wallet compromise, browser data exfiltration, and remote control.
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- aichannelProvides fake functionality and silently executes malicious actions from dependencies
- cognikitPulled as dependency; contains C2 configuration and malicious functionality
- aiassistcorePulled as dependency; contains C2 configuration and malicious functionality
A coordinated malicious package campaign was discovered on PyPI involving multiple packages designed to work together as dependencies. The primary package aichannel provides fake functionality while silently executing malicious code from its dependencies cognikit and aiassistcore, which contain the actual C2 configuration and malicious payloads.\n\nThe malicious functionality includes cryptocurrency wallet address replacement (redirecting to attacker-controlled addresses), browser data exfiltration, keylogging, clipboard monitoring, persistence mechanisms, and remote access capabilities. The packages appear designed to be used as dependencies in malicious interview assessment platforms or cryptocurrency-related projects.\n\nThe indicators of compromise and tactics, techniques, and procedures (TTPs) are consistent with North Korea's "Contagious Interview" campaign. The attack chain leverages dependency relationships to distribute and execute malicious code across multiple packages, increasing the likelihood of infection through transitive dependencies.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious packages across package ecosystems.
Indicators of compromise
- Packages
- aichannel
- cognikit
- aiassistcore
Remediation
- Immediately remove or uninstall aichannel, cognikit, and aiassistcore from all systems and development environments
- Audit all systems that installed these packages for signs of compromise including wallet address modifications, browser extensions, and unauthorized remote access
- Review browser extensions and remove any suspicious or unfamiliar extensions
- Change cryptocurrency wallet addresses and verify no unauthorized transactions occurred
- Check for keylogger activity and clipboard monitoring; consider credential rotation on affected systems
- Monitor for C2 communication to the attacker-controlled servers identified in the IoCs
- Review dependency trees in projects to identify any transitive dependencies on these malicious packages
- Implement package verification and scanning in CI/CD pipelines to detect malicious packages before installation
Sources
- GitHub Advisory GHSA-cj74-jpjj-63qf · GitHub Advisory Database
Cite this entry
"Malicious code in aichannel (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-aichannel-pypi-1twu47
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in cognikit (PyPI)
Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiprepkit (PyPI)
Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in catalogai (PyPI)
Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiassistcore (PyPI)
Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit