Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in cognikit (PyPI)

Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; packages distributed via PyPI with potential for widespread installation via dependency chains
Ecosystems
Attack vectors
Threat actor
Affected entities
  • cognikitPyPI package containing C2 configuration and malicious functionality
  • aiassistcorePyPI package containing C2 configuration and malicious functionality
  • aichannelPyPI package providing fake functionality while silently executing malicious actions from dependencies

A coordinated campaign distributing malicious Python packages via PyPI was identified and attributed to North Korea's "Contagious Interview" campaign. The affected packages include cognikit, aiassistcore, and aichannel, which were designed to be pulled as dependencies in downstream projects.\n\nThe malicious functionality includes cryptocurrency wallet address replacement (substituting victim addresses with attacker-controlled ones), browser data exfiltration, keylogging, clipboard manipulation, and remote access capabilities. Some packages (like aichannel) provide fake legitimate functionality while silently executing malicious code from their dependencies.\n\nThe packages were distributed through PyPI and appear to have been used as dependencies in malicious interview assessment platforms and cryptocurrency-related projects. The IoCs and tactics are consistent with previously documented North Korea-attributed activity.\n\nThe campaign was identified and credited to the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • cognikit
  • aiassistcore
  • aichannel

Remediation

  • Immediately remove or uninstall cognikit, aiassistcore, and aichannel from all systems
  • Audit all projects and dependencies that may have pulled these packages, particularly those related to interview assessments or cryptocurrency applications
  • Regenerate all cryptocurrency wallet addresses and private keys on affected systems
  • Scan systems for malicious browser extensions and remove any suspicious extensions
  • Review browser history and data for signs of exfiltration
  • Change all passwords and credentials on affected systems
  • Monitor for unauthorized remote access or command execution
  • Implement dependency scanning and verification in CI/CD pipelines to detect malicious packages
  • Review PyPI package sources and use only verified, trusted packages

Sources

  1. GitHub Advisory GHSA-h78x-87rw-9vm8 · GitHub Advisory Database

Cite this entry

"Malicious code in cognikit (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-cognikit-pypi-av3pve

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in aiprepkit (PyPI)

    Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in catalogai (PyPI)

    Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in aiassistcore (PyPI)

    Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in ailaunchkit (PyPI)

    A coordinated campaign of malicious Python packages on PyPI (ailaunchkit, cognikit, aiassistcore, aichannel) was discovered containing infostealer malware. The packages implement cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit