Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in pytablute (PyPI)

The PyPI package pytablute contained malicious code that executes hidden functionality during import or use, downloads second-stage payloads, and establishes persistent remote command execution capabilities. The package was part of a broader 2025-11-spellcheckers malicious campaign.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on installation prevalence of pytablute
Ecosystems
Attack vectors
Threat actor
Affected entities
  • pytablutePyPI package containing malicious code

The pytablute package on PyPI was identified as containing malicious code designed to execute hidden functionality when the library is imported or used. The malware downloads second-stage code from a remote host and establishes a background process that periodically connects to an attacker-controlled server awaiting command execution.\n\nThe malicious behavior includes obfuscation techniques, remote script download and execution, and the ability to execute remote commands on the victim's machine, likely restricted to a specific command set. This package was part of a coordinated malicious campaign labeled 2025-11-spellcheckers.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages repository (MAL-2026-13685), which tracks confirmed malicious packages across package ecosystems.

Indicators of compromise

Packages
  • pytablute

Remediation

  • Remove pytablute from all systems immediately
  • Audit systems that installed pytablute for signs of compromise, including unexpected network connections and process execution
  • Review logs for any remote command execution or data exfiltration
  • Consider the system compromised and perform full security assessment
  • Monitor for indicators of the 2025-11-spellcheckers campaign on affected systems

Sources

  1. GitHub Advisory GHSA-p4h7-5jh2-3rpc · GitHub Advisory Database

Cite this entry

"Malicious code in pytablute (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 10, 2026; last updated August 10, 2026. https://supplychainattack.org/incident/malicious-code-in-pytablute-pypi-yfljd9

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-c (npm)

    The npm package @years19/n8n-nodes-utils-helper-c contained a malicious postinstall script that downloads a trojanized Python multidict module from an attacker-controlled server and injects it into the system's Python site-packages directory, enabling arbitrary code execution on any subsequent Python invocation.

    npmPyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

    The npm package @years19/n8n-nodes-utils-helper-d contained malicious code that downloads and executes a Python DDoS/offensive-tooling dropper on installation. The package impersonates a legitimate n8n community node but performs unauthorized system reconnaissance and beacons host identity to an attacker-controlled endpoint.

    npmPyPICompromised packageTyposquatting
  3. resolvedcritical

    Malicious code in @years18/n8n-nodes-utils-helper-y (npm)

    The npm package @years18/n8n-nodes-utils-helper-y contained malicious code in its postinstall hook that downloads and executes attacker-controlled Python toolkits (mhddos, pyroxy-full, impacket), persists them in the user's Python site-packages, and exfiltrates host information to an attacker-controlled endpoint. Installation triggers immediate code execution and establishes persistence.

    npmPyPICompromised package
  4. resolvedcritical

    Malicious code in @years19/n8n-nodes-utils-helper-b (npm)

    The npm package @years19/n8n-nodes-utils-helper-b contained malicious code disguised as an n8n workflow utility. The postinstall hook executed reconnaissance, downloaded and extracted a Python tarball with TLS verification disabled, and exfiltrated system information to an attacker-controlled domain.

    npmPyPICompromised package