Malicious code in instalogin1234 (PyPI)
The instalogin1234 package on PyPI contained malicious code that harvested user credentials. When users attempted to log in via the fake Instagram CLI, their credentials were exfiltrated to a Discord channel before displaying the legitimate Instagram website.
- Disclosed
- Last updated
- Blast radius
- Users who installed the malicious instalogin1234 package from PyPI
- Ecosystems
- Attack vectors
- Affected entities
- instalogin1234Malicious package on PyPI
The instalogin1234 package, distributed on PyPI, was identified as malicious by the OpenSSF malicious-packages project. The package masqueraded as an Instagram CLI tool with login functionality.\n\nThe malicious code intercepted user credentials entered during the login process and exfiltrated them to a Discord channel. After credential theft, the package displayed the legitimate Instagram website to the user, creating a convincing social engineering attack.\n\nThis campaign (2026-08-instalogin1234) was classified as a credential infostealer with clear malicious intent. The package has been identified and cataloged by the OpenSSF malicious-packages repository.
Indicators of compromise
- Packages
- instalogin1234
Remediation
- Remove the instalogin1234 package immediately from any systems where it was installed
- Audit PyPI package installations for the presence of instalogin1234
- If credentials were entered into the fake login, assume they are compromised and change passwords on affected accounts
- Monitor Discord webhooks and channels for any exfiltrated credential data
- Review PyPI package dependencies to ensure no other malicious packages are present
Sources
- GitHub Advisory GHSA-7929-ff6q-qmmh · GitHub Advisory Database
Cite this entry
"Malicious code in instalogin1234 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 3, 2026; last updated August 3, 2026. https://supplychainattack.org/incident/malicious-code-in-instalogin1234-pypi-gvi6ek
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in wacve-utils (PyPI)
The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.
PyPICompromised package - containedcritical
Malicious code in trongriden (PyPI)
Malicious package trongriden published to PyPI designed for private key exfiltration, part of a broader 2025-04-tronix campaign targeting cryptocurrency users. No known usage has been reported.
2025 04 TronixPyPICompromised package - containedhigh
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.
PyPICompromised package - resolvedhigh
Malicious code in nvtorch-oot-nightly (PyPI)
The PyPI package nvtorch-oot-nightly contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package