Malicious code in cryptgraphy (PyPI)
A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.
- Disclosed
- Last updated
- Blast radius
- Any user who installed the malicious cryptgraphy package from PyPI during the active distribution window.
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- cryptgraphyTyposquatting package on PyPI
A malicious package named cryptgraphy was discovered on PyPI, identified as part of the 2026-08-mlflow-otel-instrumentor campaign. The package employs typosquatting to mimic legitimate cryptography libraries and downloads a remote executable during installation.
The executable exhibits multiple malicious behaviors including attempts to establish persistence through systemd services, cryptocurrency mining functionality, and network scanning/propagation capabilities. The remote executable was noted as broken, suggesting incomplete or hastily deployed malware.
The campaign shows similarities to the 2026-08-boto4 incident and was identified and credited to the OpenSSF's malicious-packages repository. The package has been flagged as containing clearly malicious intent consistent with infostealers and worm-like propagation behavior.
Indicators of compromise
- Packages
- cryptgraphy
Remediation
- Immediately uninstall the cryptgraphy package if installed: pip uninstall cryptgraphy
- Audit systems for signs of persistence mechanisms (systemd service files, cron jobs)
- Monitor for cryptocurrency mining processes and unusual network activity
- Review system logs for evidence of execution and network scanning
- Use the legitimate cryptography package (note correct spelling) from PyPI instead
- Implement package verification and allowlisting policies to prevent typosquatting attacks
Sources
- GitHub Advisory GHSA-2v43-g59q-gxp6 · GitHub Advisory Database
Cite this entry
"Malicious code in cryptgraphy (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 23, 2026; last updated August 23, 2026. https://supplychainattack.org/incident/malicious-code-in-cryptgraphy-pypi-12q9mz
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
PyPITyposquattingCompromised package - containedcritical
Malicious code in @years19/n8n-nodes-utils-helper-d (npm)
The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.
npmPyPICompromised packageTyposquatting - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package