Malicious code in cfgzen (PyPI)
Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.
- Disclosed
- Last updated
- Blast radius
- All users who installed affected versions of cfgzen from PyPI
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- cfgzenPyPI package containing malicious native module
The cfgzen package on PyPI contained malicious code embedded within a native module that was active since version 1.0.6. The native module downloads an encrypted blob which is decrypted into an executable infostealer.
The malicious functionality includes downloading and executing remote executables, exfiltrating environment variables, detecting sandbox environments for evasion, and persisting through PTH (Python Path Hook) mechanisms. The code uses obfuscation techniques to conceal its intent.
The malicious campaign was identified as 2026-07-cfgzen and credited to the OpenSSF's malicious-packages repository. The package represents a clear supply chain compromise with direct impact on any system that installed the affected versions.
Indicators of compromise
- Packages
- cfgzen
Remediation
- Immediately uninstall cfgzen from all systems
- Audit systems that had cfgzen installed for signs of compromise, including environment variable exfiltration and unauthorized network connections
- Review environment variables and secrets that may have been exposed
- Monitor for indicators of the infostealer malware execution
- Update to a patched version of cfgzen if one becomes available, or use an alternative package
- Check PyPI and security advisories for updated guidance on safe versions
Sources
- GitHub Advisory GHSA-r2w6-7pgv-644h · GitHub Advisory Database
Cite this entry
"Malicious code in cfgzen (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 28, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-cfgzen-pypi-6qhl80
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials
PyPI package mrmustard version 0.7.4 was compromised with malicious code that stole SSH keys, AWS credentials, and Kubernetes credentials upon import. The malicious version has been removed from PyPI.
PyPICompromised package - resolvedcritical
Malicious code in ycodestyle (PyPI)
Malicious code was distributed in the ycodestyle package on PyPI as part of a campaign distributing 900+ malicious packages. The malicious packages infected local browsers with extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package - resolvedcritical
Malicious code in ai-cypher (PyPI)
The ai-cypher package on PyPI contained malicious code in a compiled native extension that exfiltrates sensitive Telegram files upon import. The package was identified and cataloged by the OpenSSF malicious-packages project.
2025 12 AI CypherPyPICompromised package - resolvedcritical
Malicious code in yfnance (PyPI)
Attacker distributed 900+ malicious packages via PyPI, including yfnance, which installed malicious browser extensions designed to manipulate clipboard contents and replace cryptocurrency wallet addresses.
PyPICompromised package