Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in libasync (PyPI)

The PyPI package libasync contained malicious code in a native extension that downloads and executes remote binaries, establishes persistence via registry keys, and performs cryptomining. The package was part of the 2026-08-libasync campaign and has been identified and documented by the OpenSSF.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation count and user environment exposure
Ecosystems
Attack vectors
Threat actor
Affected entities
  • libasyncPyPI package containing malicious code in native extension

The libasync package on PyPI was found to contain malicious code embedded in a native extension. During import, the obfuscated code downloads a malicious remote executable and establishes persistence through Windows registry keys.

The malicious payload appears to be used for cryptomining purposes. The package includes anti-sandbox detection capabilities and was part of a coordinated campaign (2026-08-libasync) that shares infrastructure with the earlier 2026-07-pyqt6darktheme campaign.

The malicious package was identified and credited to the OpenSSF's malicious-packages repository (MAL-2026-14308). The incident was disclosed on 2026-08-20 via GitHub Security Advisory GHSA-7vpc-7xx6-5v47.

Indicators of compromise

Packages
  • libasync

Remediation

  • Immediately uninstall the libasync package from all affected systems
  • Scan systems for the presence of downloaded malicious binaries and registry persistence mechanisms
  • Review system logs for suspicious process execution and network connections to attacker infrastructure
  • Check for signs of unauthorized cryptocurrency mining activity
  • Update to a clean version of any legitimate package that may replace libasync, or identify alternative packages
  • Monitor for indicators of compromise related to the 2026-08-libasync and 2026-07-pyqt6darktheme campaigns

Sources

  1. GitHub Advisory GHSA-7vpc-7xx6-5v47 · GitHub Advisory Database

Cite this entry

"Malicious code in libasync (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 20, 2026; last updated August 20, 2026. https://supplychainattack.org/incident/malicious-code-in-libasync-pypi-1cy91l

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  3. containedcritical

    Malicious code in scrambleeer (PyPI)

    The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.

    2026 08 ScrambleeerPyPICompromised package
  4. containedcritical

    Malicious code in boto4 (PyPI)

    A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.

    2026 08 Boto4PyPICompromised package