Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in fast-hashes (PyPI)

A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation count and execution scope
Ecosystems
Attack vectors
Threat actor
Affected entities
  • fast-hashesMalicious package on PyPI; imitates name of a popular library

The malicious package fast-hashes was discovered on PyPI as part of the 2026-08-flasq campaign. The package uses typosquatting to mimic the name of a popular library and is designed to execute malicious code during the installation process.

The attack works by overriding the install command in setup.py with obfuscated code. When a user installs the package, this code downloads and executes a remote malicious executable without the user's knowledge or consent.

The malware is confirmed to exfiltrate cryptocurrency wallet data and likely steals additional sensitive information from the compromised system. The incident was identified and credited to the OpenSSF's malicious-packages repository.

Users who installed this package should immediately assume their systems are compromised and take appropriate remediation steps.

Indicators of compromise

Packages
  • fast-hashes

Remediation

  • Immediately uninstall the fast-hashes package from all affected systems
  • Assume any system that installed fast-hashes is compromised; perform full security audit and malware scan
  • Rotate all cryptocurrency wallet credentials and private keys from affected systems
  • Review system logs for suspicious activity and data exfiltration
  • Monitor cryptocurrency wallets for unauthorized transactions
  • Check for and remove any remote executables or persistence mechanisms installed by the malware
  • Update pip and verify package integrity for all other installed packages

Sources

  1. GitHub Advisory GHSA-jmww-p7fc-wmqh · GitHub Advisory Database

Cite this entry

"Malicious code in fast-hashes (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-fast-hashes-pypi-po1fn7

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting
  3. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in flasq (PyPI)

    A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package