Malicious code in boto4 (PyPI)
A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.
- Disclosed
- Last updated
- Blast radius
- PyPI ecosystem; any system installing the malicious boto4 package
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- boto4Malicious package on PyPI
A malicious package named boto4 was discovered on PyPI (Python Package Index) that executes embedded executable code during installation. The package was attributed to the 2026-08-boto4 campaign and credited to the OpenSSF's malicious-packages repository.\n\nThe embedded executable is capable of multiple malicious functions: executing remote commands on the victim's machine, establishing persistence, performing cryptomining operations, exfiltrating basic system data (such as IP address and username), conducting network scanning, and propagating in a worm-style manner to other systems. All actions are controlled remotely via a Telegram bot.\n\nThe malicious package was identified with hash b928f1f0d3af6242391cc626a8601d24f60c70d862bfebe6cfe0777c13a8c0b2 and cataloged as MAL-2026-14349 in the OpenSSF's malicious packages database.
Indicators of compromise
- Packages
- boto4
- Hashes
- b928f1f0d3af6242391cc626a8601d24f60c70d862bfebe6cfe0777c13a8c0b2
Remediation
- Immediately uninstall the boto4 package from all affected systems
- Audit system logs and network traffic for signs of remote command execution, cryptomining, or data exfiltration
- Check for persistence mechanisms installed by the malware and remove them
- Scan systems for indicators of compromise related to the Telegram bot command and control
- Use legitimate boto3 package (AWS SDK) instead of boto4
- Review PyPI package installations and implement package verification practices
- Monitor for lateral movement and worm propagation attempts on the network
Sources
- GitHub Advisory GHSA-ffh8-mpww-qp8g · GitHub Advisory Database
Cite this entry
"Malicious code in boto4 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 21, 2026; last updated August 21, 2026. https://supplychainattack.org/incident/malicious-code-in-boto4-pypi-i6dk9u
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
PyPITyposquattingCompromised package - containedcritical
Malicious code in cryptgraphy (PyPI)
A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.
2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting - containedcritical
Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit