Malicious code in aiprepkit (PyPI)
Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.
- Disclosed
- Last updated
- Blast radius
- Multiple PyPI packages used as dependencies in interview assessments and cryptocurrency projects; potential impact on users of aiprepkit, cognikit, aiassistcore, and aichannel packages.
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- aiprepkitPrimary malicious package on PyPI
- cognikitDependency containing C2 configuration and malicious functionality
- aiassistcoreDependency containing C2 configuration and malicious functionality
- aichannelDependency providing fake functionality while executing malicious actions
A coordinated malicious campaign distributed infostealer malware through multiple PyPI packages. The primary package aiprepkit and related packages (cognikit, aiassistcore, aichannel) were designed to be used as dependencies in malicious interview assessments or cryptocurrency-related projects.\n\nThe malicious functionality includes cryptocurrency wallet address replacement, browser data exfiltration, remote access trojans (RAT), keylogging, clipboard manipulation, and persistence mechanisms. Some packages contained C2 configuration and core malicious functionality, while others provided fake legitimate functionality as a cover while silently executing malicious actions from their dependencies.\n\nThe indicators of compromise and tactics, techniques, and procedures (TTPs) are consistent with those previously attributed to North Korea's "Contagious Interview" campaign. The attack was discovered and credited to the OpenSSF's malicious-packages repository.\n\nThe campaign appears to have been contained, with the malicious packages identified and removed from PyPI.
Indicators of compromise
- Packages
- aiprepkit
- cognikit
- aiassistcore
- aichannel
Remediation
- Immediately uninstall aiprepkit, cognikit, aiassistcore, and aichannel from all systems
- Audit all systems that installed these packages for signs of compromise, including cryptocurrency wallet configuration changes, browser extensions, and unauthorized remote access
- Change all cryptocurrency wallet addresses and private keys on affected systems
- Scan systems for keyloggers, clipboard monitors, and other infostealer malware
- Review browser extensions and remove any suspicious or unfamiliar extensions
- Monitor for unauthorized remote access attempts and lateral movement
- Check for persistence mechanisms and remove any malicious scheduled tasks or startup entries
- Review and rotate credentials for any accounts accessed from compromised systems
- Implement package verification and dependency scanning in development workflows to prevent installation of malicious packages
Sources
- GitHub Advisory GHSA-wg77-wqj2-3733 · GitHub Advisory Database
Cite this entry
"Malicious code in aiprepkit (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-aiprepkit-pypi-d02igp
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in cognikit (PyPI)
Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in catalogai (PyPI)
Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiassistcore (PyPI)
Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in ailaunchkit (PyPI)
A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit