Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

Malicious code in launchdarkly-ai-server-sdk (PyPI)

Malicious code was published in the launchdarkly-ai-server-sdk package on PyPI that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious code.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Users who installed the malicious package version
Ecosystems
Attack vectors
Affected entities
  • launchdarkly-ai-server-sdkMalicious package on PyPI

A malicious version of launchdarkly-ai-server-sdk was published on PyPI containing code designed to exfiltrate basic system information from the host upon installation or module import. The package has no legitimate functionality beyond this data exfiltration.

The attack was implemented by overriding the install command in setup.py to execute malicious code during the package installation process. This ensures the exfiltration occurs automatically when users install the package.

The incident was identified and attributed to the OpenSSF's malicious-packages repository (MAL-2026-11519). The package was categorized as a pentest-style package with limited but confirmed harm potential, specifically targeting basic host reconnaissance data.

Indicators of compromise

Packages
  • launchdarkly-ai-server-sdk

Remediation

  • Identify and remove any installations of launchdarkly-ai-server-sdk from affected systems
  • Audit systems where the package was installed for signs of unauthorized access or data exfiltration
  • Review network logs for suspicious outbound connections from the installation period
  • Use the legitimate launchdarkly-ai-server-sdk package from the official source if the functionality is required
  • Monitor for any credentials or sensitive information that may have been exposed

Sources

  1. GitHub Advisory GHSA-8m32-rjxc-vw3m · GitHub Advisory Database

Cite this entry

"Malicious code in launchdarkly-ai-server-sdk (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malicious-code-in-launchdarkly-ai-server-sdk-pypi-19rkbt

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in alphalend-abi (PyPI)

    The alphalend-abi PyPI package contained malicious code that exfiltrates sensitive files containing SUI private keys to a private GitHub repository. The malicious behavior is triggered on package import and on every Python startup via PTH file abuse.

    2026 08 Alphalend LayoutsPyPICompromised package
  2. containedcritical

    Malicious code in alphalend-layouts (PyPI)

    The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in pydanticc (PyPI)

    The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package