Malicious code in cdktn-provider-azurerm (PyPI)
A malicious package named cdktn-provider-azurerm was published to PyPI, using typosquatting to mimic HashiCorp's legitimate cdktf-provider-azurerm. The package forces installation of an attacker-controlled base dependency (cdktn) that executes arbitrary code upon import.
- Disclosed
- Last updated
- Blast radius
- Any Python environment that installed cdktn-provider-azurerm from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- cdktn-provider-azurermMalicious package mimicking HashiCorp's cdktf-provider-azurerm
A malicious package named cdktn-provider-azurerm was discovered on PyPI, designed to deceive users into installing it instead of HashiCorp's legitimate cdktf-provider-azurerm (CDK for Terraform). The attack uses a single-character substitution (cdktf → cdktn) combined with fabricated branding ("CDK Terrain" at cdktn.io) that closely mirrors HashiCorp's official cdk.tf domain and branding.\n\nThe malicious package declares a dependency on a non-HashiCorp base package named cdktn (analogous to the legitimate cdktf). When the provider module is imported, it automatically executes import cdktn._jsii via src/cdktn_provider_azurerm/_jsii/__init__.py, causing any code shipped in the attacker-controlled cdktn base package to run in the installer's Python process.\n\nThe package metadata and README further reinforce the deception by referencing cdktn-io/cdktn-provider-azurerm and a nonexistent open-constructs/cdk-terrain issue tracker, engineered to appear identical to legitimate HashiCorp CDKTF branding and infrastructure.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- cdktn-provider-azurerm
- cdktn
Remediation
- Immediately uninstall cdktn-provider-azurerm and cdktn packages from all affected Python environments
- Verify that only the legitimate cdktf and cdktf-provider-azurerm packages (from HashiCorp) are installed
- Review package installation logs and audit any systems that may have installed these malicious packages
- Use dependency scanning tools to detect and prevent installation of typosquatted packages
- Pin dependencies to specific versions from trusted sources and use package verification mechanisms
Sources
- GitHub Advisory GHSA-698f-qxc2-w6p4 · GitHub Advisory Database
Cite this entry
"Malicious code in cdktn-provider-azurerm (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-cdktn-provider-azurerm-pypi-ilvhb9
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @years19/n8n-nodes-utils-helper-d (npm)
The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.
npmPyPICompromised packageTyposquatting - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package