Malicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code was published in the launchdarkly-ai-server-sdk package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.
- Disclosed
- Last updated
- Blast radius
- Users who installed the malicious package version
- Ecosystems
- Attack vectors
- Affected entities
- launchdarkly-ai-server-sdkMalicious package on PyPI
A malicious version of launchdarkly-ai-server-sdk was published on PyPI containing code designed to exfiltrate basic system information from the host upon installation or module import. The package has no legitimate functionality beyond this data exfiltration.
The attack was implemented by overriding the install command in setup.py to execute malicious code during the package installation process. This ensures the exfiltration occurs automatically when users install the package.
The incident was identified and attributed to the OpenSSF's malicious-packages repository (MAL-2026-11519). The package was categorized as a pentest-style package with limited but confirmed harm potential, specifically targeting basic host reconnaissance data.
Indicators of compromise
- Packages
- launchdarkly-ai-server-sdk
Remediation
- Identify and remove any installations of launchdarkly-ai-server-sdk from affected systems
- Audit systems where the package was installed for signs of unauthorized access or data exfiltration
- Review network logs for suspicious outbound connections from the installation period
- Use the legitimate launchdarkly-ai-server-sdk package from the official source if the functionality is required
- Monitor for any credentials or sensitive information that may have been exposed
Sources
- GitHub Advisory GHSA-8m32-rjxc-vw3m · GitHub Advisory Database
Cite this entry
"Malicious code in launchdarkly-ai-server-sdk (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malicious-code-in-launchdarkly-ai-server-sdk-pypi-19rkbt
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in alphalend-abi (PyPI)
The alphalend-abi PyPI package contained malicious code that exfiltrates sensitive files containing SUI private keys to a private GitHub repository. The malicious behavior is triggered on package import and on every Python startup via PTH file abuse.
2026 08 Alphalend LayoutsPyPICompromised package - containedcritical
Malicious code in alphalend-layouts (PyPI)
The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.
PyPICompromised packageMalicious commit - containedcritical
Malicious code in idnna (PyPI)
A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
PyPITyposquattingCompromised package - containedcritical
Malicious code in pydanticc (PyPI)
The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.
2026 08 FlasqPyPITyposquattingCompromised package