Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in cdktn-provider-azurerm (PyPI)

A malicious package named cdktn-provider-azurerm was published to PyPI, using typosquatting to mimic HashiCorp's legitimate cdktf-provider-azurerm. The package forces installation of an attacker-controlled base dependency (cdktn) that executes arbitrary code upon import.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any Python environment that installed cdktn-provider-azurerm from PyPI
Ecosystems
Attack vectors
Affected entities
  • cdktn-provider-azurermMalicious package mimicking HashiCorp's cdktf-provider-azurerm

A malicious package named cdktn-provider-azurerm was discovered on PyPI, designed to deceive users into installing it instead of HashiCorp's legitimate cdktf-provider-azurerm (CDK for Terraform). The attack uses a single-character substitution (cdktf → cdktn) combined with fabricated branding ("CDK Terrain" at cdktn.io) that closely mirrors HashiCorp's official cdk.tf domain and branding.\n\nThe malicious package declares a dependency on a non-HashiCorp base package named cdktn (analogous to the legitimate cdktf). When the provider module is imported, it automatically executes import cdktn._jsii via src/cdktn_provider_azurerm/_jsii/__init__.py, causing any code shipped in the attacker-controlled cdktn base package to run in the installer's Python process.\n\nThe package metadata and README further reinforce the deception by referencing cdktn-io/cdktn-provider-azurerm and a nonexistent open-constructs/cdk-terrain issue tracker, engineered to appear identical to legitimate HashiCorp CDKTF branding and infrastructure.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • cdktn-provider-azurerm
  • cdktn

Remediation

  • Immediately uninstall cdktn-provider-azurerm and cdktn packages from all affected Python environments
  • Verify that only the legitimate cdktf and cdktf-provider-azurerm packages (from HashiCorp) are installed
  • Review package installation logs and audit any systems that may have installed these malicious packages
  • Use dependency scanning tools to detect and prevent installation of typosquatted packages
  • Pin dependencies to specific versions from trusted sources and use package verification mechanisms

Sources

  1. GitHub Advisory GHSA-698f-qxc2-w6p4 · GitHub Advisory Database

Cite this entry

"Malicious code in cdktn-provider-azurerm (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-cdktn-provider-azurerm-pypi-ilvhb9

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting
  2. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  3. containedcritical

    Malicious code in flasq (PyPI)

    A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package