Malicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code was published in the launchdarkly-ai-server-sdk package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.
- Disclosed
- Last updated
- Blast radius
- Users who installed the malicious package version
- Ecosystems
- Attack vectors
- Affected entities
- launchdarkly-ai-server-sdkMalicious package on PyPI
A malicious version of launchdarkly-ai-server-sdk was published on PyPI containing code designed to exfiltrate basic system information from the host upon installation or module import. The package has no legitimate functionality beyond this data exfiltration.
The attack was implemented by overriding the install command in setup.py to execute malicious code during the package installation process. This ensures the exfiltration occurs automatically when users install the package.
The incident was identified and attributed to the OpenSSF's malicious-packages repository (MAL-2026-11519). The package was categorized as a pentest-style package with limited but confirmed harm potential, specifically targeting basic host reconnaissance data.
Indicators of compromise
- Packages
- launchdarkly-ai-server-sdk
Remediation
- Identify and remove any installations of launchdarkly-ai-server-sdk from affected systems
- Audit systems where the package was installed for signs of unauthorized access or data exfiltration
- Review network logs for suspicious outbound connections from the installation period
- Use the legitimate launchdarkly-ai-server-sdk package from the official source if the functionality is required
- Monitor for any credentials or sensitive information that may have been exposed
Sources
- GitHub Advisory GHSA-8m32-rjxc-vw3m · GitHub Advisory Database
Cite this entry
"Malicious code in launchdarkly-ai-server-sdk (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malicious-code-in-launchdarkly-ai-server-sdk-pypi-19rkbt
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in coldcard-helpers (PyPI)
The PyPI package coldcard-helpers was compromised with malicious code that exfiltrates sensitive data including environment variables, cryptocurrency private keys, and SSH keys to a Telegram channel. The malicious payload executes during package installation via a setup.py override.
PyPICompromised package - resolvedcritical
Malicious code in psbt-utils (PyPI)
The psbt-utils package on PyPI contained malicious code disguised as a hardware wallet firmware upgrader. The payload is an infostealer that exfiltrates cryptocurrency wallets, browser credentials, SSH keys, TOTP seeds, and clipboard content, with persistence mechanisms via scheduled tasks or LaunchAgent.
PyPICompromised package - resolvedcritical
Malicious code in instalogin1234 (PyPI)
The instalogin1234 package on PyPI contained malicious code that harvested user credentials. When users attempted to log in via the fake Instagram CLI, their credentials were exfiltrated to a Discord channel before displaying the legitimate Instagram website.
PyPICompromised package - resolvedcritical
Malicious code in wacve-utils (PyPI)
The PyPI package wacve-utils contained encrypted malicious code implementing an infostealer targeting Linux and Android (Termux) systems. The malware collected files, browser data, and text messages, exfiltrating them to a Telegram channel and downloading/executing remote malicious scripts.
PyPICompromised package