Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in multyproccess (PyPI)

The multyproccess package on PyPI contained malicious code that executed an infostealer during installation. The package used typosquatting to mimic a legitimate package and included functionality to exfiltrate browser data, cryptocurrency wallets, establish persistence, and monitor clipboard activity.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed the malicious multyproccess package from PyPI during the active distribution period.
Ecosystems
Attack vectors
Affected entities
  • multyproccessTyposquatting package on PyPI containing infostealer malware

The multyproccess package distributed on PyPI was identified as a malicious typosquatting package designed to deceive users into installing it. During installation, the package executed an infostealer payload by overriding the install command in setup.py.

The malware performed multiple malicious functions including exfiltration of browser data and cryptocurrency wallet information, establishment of persistence mechanisms, clipboard monitoring, and sandbox detection to evade analysis. The package employed obfuscation techniques to conceal its malicious intent.

This campaign, designated 2026-08-multyproccess, was identified and credited to the OpenSSF's malicious-packages repository. The package cloned the structure of a legitimate package while injecting the infostealer payload to compromise systems during the installation process.

Indicators of compromise

Packages
  • multyproccess

Remediation

  • Immediately uninstall the multyproccess package if installed
  • Scan systems for indicators of compromise including unauthorized persistence mechanisms
  • Review browser history and cryptocurrency wallet access logs for unauthorized activity
  • Change passwords for cryptocurrency wallets and sensitive accounts
  • Monitor clipboard activity and system processes for suspicious behavior
  • Check for and remove any persistence mechanisms established by the malware
  • Use only verified, legitimate packages from trusted sources
  • Implement package verification and scanning in dependency management workflows

Sources

  1. GitHub Advisory GHSA-32gv-h6qj-hjm8 · GitHub Advisory Database

Cite this entry

"Malicious code in multyproccess (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 24, 2026; last updated August 24, 2026. https://supplychainattack.org/incident/malicious-code-in-multyproccess-pypi-5yc5nf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in cryptgraphy (PyPI)

    A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

    2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting
  3. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting
  4. containedcritical

    Malicious code in fastapii (PyPI)

    The fastapii package on PyPI is a typosquatting attack imitating the popular FastAPI library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package