Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in neutrl-core (PyPI)

Malicious code was discovered in the neutrl-core PyPI package designed to exfiltrate sensitive credentials including environment variables, SSH keys, and dotenv files. The malicious functionality was hidden in a function disguised as telemetry and activated via commands from an attacker-controlled endpoint. The attack campaign involved a fake GitHub account with backdated commits to establish false credibility.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any Python project that installed affected versions of neutrl-core from PyPI
Ecosystems
Attack vectors
Affected entities
  • neutrl-corePyPI package containing malicious code

The neutrl-core package on PyPI contained intentionally malicious code as part of a coordinated supply chain attack campaign. The malicious code was embedded in a dependency function disguised as telemetry functionality, designed to remain dormant until activated by commands from an attacker-controlled endpoint.

The attack was designed to exfiltrate sensitive data including environment variables, SSH keys, dotenv files, and other credentials from compromised systems. Additionally, the malicious code included functionality to execute remote commands on victim machines, likely limited to a specific set of attacker-defined operations. The package also contained code to ensure an attacker-controlled endpoint was always included in blockchain endpoint configurations, even if users provided their own endpoints.

The attack campaign involved social engineering tactics, including a fake GitHub account that published repositories with backdated commits to establish false credibility and history. While dependent packages did not directly use the malicious code in analyzed versions, they were clearly prepared for downstream exploitation in the supply chain.

The incident was identified and credited to the OpenSSF's malicious-packages project.

Indicators of compromise

Packages
  • neutrl-core

Remediation

  • Immediately remove or uninstall neutrl-core from all systems and projects
  • Audit all systems that had neutrl-core installed for signs of credential exfiltration or unauthorized access
  • Rotate all SSH keys, API tokens, and credentials that may have been exposed on systems running affected versions
  • Review environment variables and dotenv files for unauthorized access or exfiltration
  • Check blockchain endpoint configurations for unauthorized attacker-controlled endpoints
  • Monitor for suspicious outbound connections to attacker-controlled infrastructure
  • Review git commit history and account activity for any suspicious backdated commits or unauthorized changes
  • Update to a patched version of neutrl-core once verified safe, or use an alternative package

Sources

  1. GitHub Advisory GHSA-mphw-49c2-f7hr · GitHub Advisory Database

Cite this entry

"Malicious code in neutrl-core (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 10, 2026; last updated August 10, 2026. https://supplychainattack.org/incident/malicious-code-in-neutrl-core-pypi-x6q5j4

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-c (npm)

    The npm package @years19/n8n-nodes-utils-helper-c contained a malicious postinstall script that downloads a trojanized Python multidict module from an attacker-controlled server and injects it into the system's Python site-packages directory, enabling arbitrary code execution on any subsequent Python invocation.

    npmPyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in alphalend-layouts (PyPI)

    The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in aiassistcore (PyPI)

    Multiple malicious PyPI packages (aiassistcore, cognikit, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, and remote access capabilities. The campaign, attributed to North Korean threat actors, uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. containedcritical

    Malicious code in catalogai (PyPI)

    Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit