Malicious code in instalogin1234 (PyPI)
The instalogin1234 package on PyPI contained malicious code that harvested user credentials. When users attempted to log in via the fake Instagram CLI, their credentials were exfiltrated to a Discord channel before displaying the legitimate Instagram website.
- Disclosed
- Last updated
- Blast radius
- Users who installed the malicious instalogin1234 package from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- instalogin1234Malicious package on PyPI
The instalogin1234 package, distributed on PyPI, was identified as malicious by the OpenSSF malicious-packages project. The package masqueraded as an Instagram CLI tool with login functionality.\n\nThe malicious code intercepted user credentials entered during the login process and exfiltrated them to a Discord channel. After credential theft, the package displayed the legitimate Instagram website to the user, creating a convincing social engineering attack.\n\nThis campaign (2026-08-instalogin1234) was classified as a credential infostealer with clear malicious intent. The package has been identified and cataloged by the OpenSSF malicious-packages repository.
Indicators of compromise
- Packages
- instalogin1234
Remediation
- Remove the instalogin1234 package immediately from any systems where it was installed
- Audit PyPI package installations for the presence of instalogin1234
- If credentials were entered into the fake login, assume they are compromised and change passwords on affected accounts
- Monitor Discord webhooks and channels for any exfiltrated credential data
- Review PyPI package dependencies to ensure no other malicious packages are present
Sources
- GitHub Advisory GHSA-7929-ff6q-qmmh · GitHub Advisory Database
Cite this entry
"Malicious code in instalogin1234 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 3, 2026; last updated August 3, 2026. https://supplychainattack.org/incident/malicious-code-in-instalogin1234-pypi-gvi6ek
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in riakcs (PyPI)
The riakcs package on PyPI contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload when installed.
PyPICompromised package - containedcritical
Malicious code in fastapii (PyPI)
The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package