Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in boto4 (PyPI)

A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
PyPI ecosystem; any system installing the malicious boto4 package
Ecosystems
Attack vectors
Threat actor
Affected entities
  • boto4Malicious package on PyPI

A malicious package named boto4 was discovered on PyPI (Python Package Index) that executes embedded executable code during installation. The package was attributed to the 2026-08-boto4 campaign and credited to the OpenSSF's malicious-packages repository.\n\nThe embedded executable is capable of multiple malicious functions: executing remote commands on the victim's machine, establishing persistence, performing cryptomining operations, exfiltrating basic system data (such as IP address and username), conducting network scanning, and propagating in a worm-style manner to other systems. All actions are controlled remotely via a Telegram bot.\n\nThe malicious package was identified with hash b928f1f0d3af6242391cc626a8601d24f60c70d862bfebe6cfe0777c13a8c0b2 and cataloged as MAL-2026-14349 in the OpenSSF's malicious packages database.

Indicators of compromise

Packages
  • boto4
Hashes
  • b928f1f0d3af6242391cc626a8601d24f60c70d862bfebe6cfe0777c13a8c0b2

Remediation

  • Immediately uninstall the boto4 package from all affected systems
  • Audit system logs and network traffic for signs of remote command execution, cryptomining, or data exfiltration
  • Check for persistence mechanisms installed by the malware and remove them
  • Scan systems for indicators of compromise related to the Telegram bot command and control
  • Use legitimate boto3 package (AWS SDK) instead of boto4
  • Review PyPI package installations and implement package verification practices
  • Monitor for lateral movement and worm propagation attempts on the network

Sources

  1. GitHub Advisory GHSA-ffh8-mpww-qp8g · GitHub Advisory Database

Cite this entry

"Malicious code in boto4 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 21, 2026; last updated August 21, 2026. https://supplychainattack.org/incident/malicious-code-in-boto4-pypi-i6dk9u

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in cryptgraphy (PyPI)

    A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

    2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting
  3. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  4. containedcritical

    Malicious code in reqcrypts (PyPI)

    The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

    2026 08 ReqcryptPyPICompromised packageMalicious commit