Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in ailaunchkit (PyPI)

A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; packages distributed via PyPI with potential for widespread installation
Ecosystems
Attack vectors
Threat actor
Affected entities
  • ailaunchkitPrimary malicious package on PyPI
  • cognikitDependency containing C2 configuration and malicious functionality
  • aiassistcoreDependency containing C2 configuration and malicious functionality
  • aichannelProvides fake functionality while executing malicious actions from dependencies

A malicious package campaign targeting PyPI was identified involving multiple packages designed to work together as dependencies. The primary package ailaunchkit, along with cognikit, aiassistcore, and aichannel, contained intentionally injected malicious code.

The malware implements several attack capabilities: cryptocurrency wallet address replacement (redirecting to attacker-controlled addresses), exfiltration of browser data, keylogging, clipboard monitoring, and remote access functionality. Some packages (cognikit, aiassistcore) contain C2 configuration and core malicious logic, while others (aichannel) provide fake functionality as a cover while silently executing malicious actions from their dependencies.

The indicators of compromise and tactics are consistent with North Korea's "Contagious Interview" campaign. The packages appear designed to be used as dependencies in malicious interview assessment tools or cryptocurrency-related projects, suggesting targeted distribution rather than mass infection.

The incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • ailaunchkit
  • cognikit
  • aiassistcore
  • aichannel

Remediation

  • Immediately uninstall ailaunchkit, cognikit, aiassistcore, and aichannel from all systems
  • Audit all systems that installed these packages for signs of compromise (wallet address changes, browser extensions, exfiltrated data)
  • Rotate cryptocurrency wallet addresses and verify no unauthorized transactions occurred
  • Scan systems for malicious browser extensions and remove any suspicious extensions
  • Review browser history and data for unauthorized access or exfiltration
  • Check for persistence mechanisms and remote access tools on affected systems
  • Monitor for keylogging activity and clipboard access on affected systems
  • Review PyPI package dependencies to ensure no other malicious packages are installed
  • Implement package verification and scanning in dependency management workflows

Sources

  1. GitHub Advisory GHSA-8x7r-7883-gjgh · GitHub Advisory Database

Cite this entry

"Malicious code in ailaunchkit (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-ailaunchkit-pypi-gg3vhm

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in cognikit (PyPI)

    Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in aiprepkit (PyPI)

    Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in catalogai (PyPI)

    Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in aiassistcore (PyPI)

    Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit