Malicious code in catalogai (PyPI)
Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.
- Disclosed
- Last updated
- Blast radius
- Unknown; packages distributed via PyPI with potential for widespread installation
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- catalogaiPrimary malicious package on PyPI
- cognikitDependency containing C2 configuration and malicious functionality
- aiassistcoreDependency containing C2 configuration and malicious functionality
- aichannelDependency providing fake functionality while executing malicious actions
A coordinated malicious package campaign was discovered on PyPI involving multiple packages with interconnected functionality. The primary package catalogai and its dependencies (cognikit, aiassistcore, aichannel) were designed to work together, with some packages containing C2 configuration and malicious code while others provided fake functionality as cover.
The malware implements infostealer capabilities including keylogging, clipboard monitoring, browser data exfiltration, and persistence mechanisms. A key feature is the replacement of cryptocurrency wallet addresses with attacker-controlled addresses, with the malicious configuration downloaded from a C2 server. The packages also establish remote access capabilities on infected systems and inject malicious browser extensions.
The indicators of compromise and tactics are consistent with North Korea's "Contagious Interview" campaign. The packages appear designed to be used as dependencies in fake interview assessment tools or cryptocurrency-related projects to maximize installation rates among target users.
The campaign was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- catalogai
- cognikit
- aiassistcore
- aichannel
Remediation
- Immediately uninstall catalogai, cognikit, aiassistcore, and aichannel from all systems
- Audit all systems that installed these packages for signs of compromise, including cryptocurrency wallet configuration changes, browser extensions, and unauthorized remote access
- Review browser history and data for exfiltration indicators
- Change all cryptocurrency wallet addresses and verify wallet contents
- Scan systems for persistence mechanisms and malicious browser extensions
- Monitor for C2 communication to the attacker-controlled servers
- Review PyPI package dependencies to identify and remove any packages that depend on the malicious packages
- Implement package verification and scanning in dependency management workflows
Sources
- GitHub Advisory GHSA-6cqw-65hg-qqm3 · GitHub Advisory Database
Cite this entry
"Malicious code in catalogai (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-catalogai-pypi-1j77k2
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in cognikit (PyPI)
Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiprepkit (PyPI)
Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in aiassistcore (PyPI)
Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.
Contagious InterviewPyPICompromised packageMalicious commit - containedcritical
Malicious code in ailaunchkit (PyPI)
A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.
Contagious InterviewPyPICompromised packageMalicious commit