Malicious code in libasync (PyPI)
The PyPI package libasync contained malicious code in a native extension that downloads and executes remote binaries, establishes persistence via registry keys, and performs cryptomining. The package was part of the 2026-08-libasync campaign and has been identified and documented by the OpenSSF.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count and user environment exposure
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- libasyncPyPI package containing malicious code in native extension
The libasync package on PyPI was found to contain malicious code embedded in a native extension. During import, the obfuscated code downloads a malicious remote executable and establishes persistence through Windows registry keys.
The malicious payload appears to be used for cryptomining purposes. The package includes anti-sandbox detection capabilities and was part of a coordinated campaign (2026-08-libasync) that shares infrastructure with the earlier 2026-07-pyqt6darktheme campaign.
The malicious package was identified and credited to the OpenSSF's malicious-packages repository (MAL-2026-14308). The incident was disclosed on 2026-08-20 via GitHub Security Advisory GHSA-7vpc-7xx6-5v47.
Indicators of compromise
- Packages
- libasync
Remediation
- Immediately uninstall the libasync package from all affected systems
- Scan systems for the presence of downloaded malicious binaries and registry persistence mechanisms
- Review system logs for suspicious process execution and network connections to attacker infrastructure
- Check for signs of unauthorized cryptocurrency mining activity
- Update to a clean version of any legitimate package that may replace libasync, or identify alternative packages
- Monitor for indicators of compromise related to the 2026-08-libasync and 2026-07-pyqt6darktheme campaigns
Sources
- GitHub Advisory GHSA-7vpc-7xx6-5v47 · GitHub Advisory Database
Cite this entry
"Malicious code in libasync (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 20, 2026; last updated August 20, 2026. https://supplychainattack.org/incident/malicious-code-in-libasync-pypi-1cy91l
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
PyPITyposquattingCompromised package - containedcritical
Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in scrambleeer (PyPI)
The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.
2026 08 ScrambleeerPyPICompromised package - containedcritical
Malicious code in boto4 (PyPI)
A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.
2026 08 Boto4PyPICompromised package