Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in envprovision (PyPI)

The PyPI package envprovision contained malicious code that downloads and executes a heavily obfuscated infostealer ("Snow Stealer") on Windows systems. The malware collects browser data, modifies cryptocurrency wallet applications, and attempts to cover its tracks by cleaning logs and removing downloaded files.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
PyPI users who installed affected versions of envprovision; Windows systems targeted for malware deployment and credential theft.
Ecosystems
Attack vectors
Affected entities
  • envprovisionPyPI package containing malicious code

The envprovision package on PyPI was found to contain malicious code designed to evade detection and execute harmful payloads. The package exports functions that hide the malicious functionality from casual inspection.\n\nOn Windows systems, the malware downloads and installs a remote executable disguised as a system utility. The installed payload is a heavily obfuscated malware variant identified as "Snow Stealer," which includes multiple sandbox evasion techniques to avoid detection in analysis environments.\n\nThe infostealer collects sensitive data including browser credentials and modifies cryptocurrency wallet applications, likely to facilitate theft of digital assets. After execution, the malware attempts to cover its tracks by cleaning system logs and removing downloaded files to hinder forensic analysis.\n\nThe campaign was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious packages across package ecosystems.

Indicators of compromise

Packages
  • envprovision

Remediation

  • Immediately uninstall envprovision from all systems, particularly Windows machines
  • Scan affected systems with updated antimalware tools for Snow Stealer and related malware signatures
  • Reset passwords for all accounts accessed from affected systems, especially cryptocurrency wallets and browser-stored credentials
  • Review browser history and installed extensions on affected systems for signs of compromise
  • Monitor cryptocurrency wallets for unauthorized transactions
  • Check system logs for evidence of malware execution and data exfiltration before logs were cleaned
  • Update PyPI package dependencies to exclude envprovision and verify no malicious replacements are installed

Sources

  1. GitHub Advisory GHSA-xr9j-7gjp-x8fg · GitHub Advisory Database

Cite this entry

"Malicious code in envprovision (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 24, 2026; last updated August 24, 2026. https://supplychainattack.org/incident/malicious-code-in-envprovision-pypi-n4a465

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in cryptgraphy (PyPI)

    A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

    2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting
  2. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  3. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  4. containedcritical

    Malicious code in requests-crypt (PyPI)

    The PyPI package requests-crypt contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

    PyPICompromised package