Malicious code in scrambleeeer (PyPI)
The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on installation count and deployment scope
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- scrambleeeerPyPI package containing malicious reverse shell code
The scrambleeeer package on PyPI was found to contain malicious code designed to create a reverse shell connection to a hardcoded attacker-controlled location. When the library is used, this code executes automatically, providing the attacker with the ability to run arbitrary commands on the victim's machine.
This malicious package was identified and attributed to campaign 2026-08-scrambleeer. The malicious functionality is hidden within the library's normal usage, making it difficult for users to detect without code review.
The incident has been documented by the OpenSSF's malicious-packages repository (MAL-2026-14358) and reported via GitHub Security Advisory GHSA-xw2j-24j3-3282. The package hash 52bcde495e195edfc164c36aa7f704643c3171eaffc477c28de4b60c7dd2d414 has been associated with the malicious version.
Indicators of compromise
- Packages
- scrambleeeer
- Hashes
- 52bcde495e195edfc164c36aa7f704643c3171eaffc477c28de4b60c7dd2d414
Remediation
- Immediately uninstall scrambleeeer from all systems
- Audit systems that had scrambleeeer installed for signs of unauthorized access or reverse shell connections
- Review network logs for outbound connections to the hardcoded attacker location
- Check for any unauthorized command execution or privilege escalation on affected systems
- Use a package manager to verify no malicious versions of scrambleeeer are installed
- Monitor for similar malicious packages in the 2026-08-scrambleeer campaign
Sources
- GitHub Advisory GHSA-xw2j-24j3-3282 · GitHub Advisory Database
Cite this entry
"Malicious code in scrambleeeer (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 22, 2026; last updated August 22, 2026. https://supplychainattack.org/incident/malicious-code-in-scrambleeeer-pypi-1j3vxo
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in mlflow-otel-instrumentor (PyPI)
A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.
PyPITyposquattingCompromised package - containedcritical
Malicious code in cryptgraphy (PyPI)
A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.
2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit - containedcritical
Malicious code in boto4 (PyPI)
A malicious package named boto4 was published to PyPI containing embedded executable code capable of cryptomining, remote command execution, persistence, data exfiltration, and worm-style propagation controlled via Telegram bot. The package was identified and attributed to the 2026-08-boto4 campaign by the OpenSSF.
2026 08 Boto4PyPICompromised package