Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in dlmm-sdk (PyPI)

dlmm-sdk, a PyPI package, was compromised with malicious code that exfiltrates environment variables, credential files, and cryptocurrency wallet directory listings upon import. The malicious campaign (2026-08-dlmm) was identified and attributed to OpenSSF's malicious-packages repository.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed dlmm-sdk from PyPI during the malicious distribution period
Ecosystems
Attack vectors
Affected entities
  • dlmm-sdkPyPI package containing malicious code

The dlmm-sdk package on PyPI was found to contain malicious code that executes during package import. The malware performs credential and environment variable exfiltration, collecting sensitive data such as API keys and authentication tokens. Additionally, the package enumerates cryptocurrency wallet directories, indicating targeting of users with digital assets.\n\nThe malicious code was identified as part of the 2026-08-dlmm campaign and credited to OpenSSF's malicious-packages project. The package exhibits clear infostealer characteristics with dependency-confusion tactics, suggesting deliberate targeting of developers in the cryptocurrency/blockchain ecosystem.\n\nUsers who installed dlmm-sdk during the malicious distribution period should assume their environment variables, credential files, and wallet information may have been compromised. Immediate remediation includes package removal, credential rotation, and security audits of affected systems.

Indicators of compromise

Packages
  • dlmm-sdk

Remediation

  • Immediately uninstall dlmm-sdk from all systems
  • Rotate all credentials and API keys that may have been exposed
  • Review environment variables and configuration files for sensitive data exposure
  • Audit cryptocurrency wallets and accounts for unauthorized access
  • Scan systems for indicators of compromise from the malware
  • Update dependency management to prevent installation of malicious versions
  • Monitor for similar packages with typosquatting or dependency-confusion tactics

Sources

  1. GitHub Advisory GHSA-jp82-pmg9-xvj9 · GitHub Advisory Database

Cite this entry

"Malicious code in dlmm-sdk (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 11, 2026; last updated August 11, 2026. https://supplychainattack.org/incident/malicious-code-in-dlmm-sdk-pypi-1wxcan

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedhigh

    Malicious code in kb-ai (PyPI)

    The kb-ai package on PyPI contained malicious code designed to demonstrate a dependency confusion attack. The package exfiltrated basic system data (IP address, username) and executed arbitrary code during installation via setup.py override.

    PyPICompromised packageDependency confusion
  2. resolvedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-b (npm)

    The npm package @years19/n8n-nodes-utils-helper-b contained malicious code disguised as an n8n workflow utility. The postinstall hook executed reconnaissance, downloaded and extracted a Python tarball with TLS verification disabled, and exfiltrated system information to an attacker-controlled domain.

    npmPyPICompromised package
  3. resolvedcritical

    Malicious code in @years18/n8n-nodes-utils-helper-y (npm)

    The npm package @years18/n8n-nodes-utils-helper-y contained malicious code in its postinstall hook that downloads and executes attacker-controlled Python toolkits (mhddos, pyroxy-full, impacket), persists them in the user's Python site-packages, and exfiltrates host information to an attacker-controlled endpoint. Installation triggers immediate code execution and establishes persistence.

    npmPyPICompromised package
  4. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting