Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in cryptgraphy (PyPI)

A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any user who installed the malicious cryptgraphy package from PyPI during the active distribution window.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • cryptgraphyTyposquatting package on PyPI

A malicious package named cryptgraphy was discovered on PyPI, identified as part of the 2026-08-mlflow-otel-instrumentor campaign. The package employs typosquatting to mimic legitimate cryptography libraries and downloads a remote executable during installation.

The executable exhibits multiple malicious behaviors including attempts to establish persistence through systemd services, cryptocurrency mining functionality, and network scanning/propagation capabilities. The remote executable was noted as broken, suggesting incomplete or hastily deployed malware.

The campaign shows similarities to the 2026-08-boto4 incident and was identified and credited to the OpenSSF's malicious-packages repository. The package has been flagged as containing clearly malicious intent consistent with infostealers and worm-like propagation behavior.

Indicators of compromise

Packages
  • cryptgraphy

Remediation

  • Immediately uninstall the cryptgraphy package if installed: pip uninstall cryptgraphy
  • Audit systems for signs of persistence mechanisms (systemd service files, cron jobs)
  • Monitor for cryptocurrency mining processes and unusual network activity
  • Review system logs for evidence of execution and network scanning
  • Use the legitimate cryptography package (note correct spelling) from PyPI instead
  • Implement package verification and allowlisting policies to prevent typosquatting attacks

Sources

  1. GitHub Advisory GHSA-2v43-g59q-gxp6 · GitHub Advisory Database

Cite this entry

"Malicious code in cryptgraphy (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 23, 2026; last updated August 23, 2026. https://supplychainattack.org/incident/malicious-code-in-cryptgraphy-pypi-12q9mz

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting
  3. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in flasq (PyPI)

    A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package