Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in cfgzen (PyPI)

Malicious code was discovered in the cfgzen PyPI package, embedded in a native module that functions as an infostealer. The malicious code downloads and executes an encrypted remote executable, with capabilities to exfiltrate environment variables and detect sandbox environments. The package has been identified as part of campaign 2026-07-cfgzen.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed affected versions of cfgzen from PyPI
Ecosystems
Attack vectors
Threat actor
Affected entities
  • cfgzenPyPI package containing malicious native module

The cfgzen package on PyPI contained malicious code embedded within a native module that was active since version 1.0.6. The native module downloads an encrypted blob which is decrypted into an executable infostealer.

The malicious functionality includes downloading and executing remote executables, exfiltrating environment variables, detecting sandbox environments for evasion, and persisting through PTH (Python Path Hook) mechanisms. The code uses obfuscation techniques to conceal its intent.

The malicious campaign was identified as 2026-07-cfgzen and credited to the OpenSSF's malicious-packages repository. The package represents a clear supply chain compromise with direct impact on any system that installed the affected versions.

Indicators of compromise

Packages
  • cfgzen

Remediation

  • Immediately uninstall cfgzen from all systems
  • Audit systems that had cfgzen installed for signs of compromise, including environment variable exfiltration and unauthorized network connections
  • Review environment variables and secrets that may have been exposed
  • Monitor for indicators of the infostealer malware execution
  • Update to a patched version of cfgzen if one becomes available, or use an alternative package
  • Check PyPI and security advisories for updated guidance on safe versions

Sources

  1. GitHub Advisory GHSA-r2w6-7pgv-644h · GitHub Advisory Database

Cite this entry

"Malicious code in cfgzen (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 28, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-cfgzen-pypi-6qhl80

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in alphalend-abi (PyPI)

    The alphalend-abi PyPI package contained malicious code that exfiltrates sensitive files containing SUI private keys to a private GitHub repository. The malicious behavior is triggered on package import and on every Python startup via PTH file abuse.

    2026 08 Alphalend LayoutsPyPICompromised package
  2. containedcritical

    Malicious code in alphalend-layouts (PyPI)

    The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in pydanticc (PyPI)

    The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package