Malicious code in fast-hashes (PyPI)
A malicious package named fast-hashes was published to PyPI, using typosquatting to imitate a legitimate library. During installation, obfuscated code downloads and executes a remote malicious executable that exfiltrates cryptocurrency wallet data and potentially other sensitive information.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count and execution scope
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- fast-hashesMalicious package on PyPI; imitates name of a popular library
The malicious package fast-hashes was discovered on PyPI as part of the 2026-08-flasq campaign. The package uses typosquatting to mimic the name of a popular library and is designed to execute malicious code during the installation process.
The attack works by overriding the install command in setup.py with obfuscated code. When a user installs the package, this code downloads and executes a remote malicious executable without the user's knowledge or consent.
The malware is confirmed to exfiltrate cryptocurrency wallet data and likely steals additional sensitive information from the compromised system. The incident was identified and credited to the OpenSSF's malicious-packages repository.
Users who installed this package should immediately assume their systems are compromised and take appropriate remediation steps.
Indicators of compromise
- Packages
- fast-hashes
Remediation
- Immediately uninstall the fast-hashes package from all affected systems
- Assume any system that installed fast-hashes is compromised; perform full security audit and malware scan
- Rotate all cryptocurrency wallet credentials and private keys from affected systems
- Review system logs for suspicious activity and data exfiltration
- Monitor cryptocurrency wallets for unauthorized transactions
- Check for and remove any remote executables or persistence mechanisms installed by the malware
- Update pip and verify package integrity for all other installed packages
Sources
- GitHub Advisory GHSA-jmww-p7fc-wmqh · GitHub Advisory Database
Cite this entry
"Malicious code in fast-hashes (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 7, 2026; last updated August 7, 2026. https://supplychainattack.org/incident/malicious-code-in-fast-hashes-pypi-po1fn7
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
PyPITyposquattingCompromised package - containedcritical
Malicious code in @years19/n8n-nodes-utils-helper-d (npm)
The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.
npmPyPICompromised packageTyposquatting - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in flasq (PyPI)
A malicious package named flasq was published on PyPI, imitating a popular library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package