Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in scrambleeer (PyPI)

The scrambleeer package on PyPI contained malicious code that establishes a reverse shell to a hardcoded location, enabling arbitrary command execution on affected systems. The malicious package was identified and cataloged by the OpenSSF malicious-packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed the malicious scrambleeer package from PyPI
Ecosystems
Attack vectors
Threat actor
Affected entities
  • scrambleeerPyPI package containing reverse shell code

The scrambleeer package distributed via PyPI contained embedded malicious code designed to create a reverse shell connection to a hardcoded attacker-controlled location. When the library was used, this code would execute automatically, granting the attacker the ability to run arbitrary commands on the victim's machine.\n\nThe malicious behavior was classified as part of the 2026-08-scrambleeer campaign and identified by the OpenSSF's malicious-packages project. The attack vector involved hiding malicious functionality within the library's normal usage pattern, making it difficult for users to detect without code inspection.\n\nThe package has been identified and documented in the OpenSSF malicious-packages repository (MAL-2026-14350), allowing the security community to track and remediate affected installations.

Indicators of compromise

Packages
  • scrambleeer

Remediation

  • Immediately uninstall the scrambleeer package from all affected systems using 'pip uninstall scrambleeer'
  • Audit systems that had scrambleeer installed for signs of unauthorized access or command execution
  • Review system logs and network connections for evidence of reverse shell activity to unknown hosts
  • Change credentials and review access logs for any accounts that may have been compromised
  • Do not reinstall scrambleeer unless a verified clean version is released by a trusted maintainer
  • Monitor PyPI and security advisories for updates on this incident

Sources

  1. GitHub Advisory GHSA-jx7v-9c55-jw2v · GitHub Advisory Database

Cite this entry

"Malicious code in scrambleeer (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 21, 2026; last updated August 21, 2026. https://supplychainattack.org/incident/malicious-code-in-scrambleeer-pypi-1bsiwf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in mlflow-otel-instrumentor (PyPI)

    A typosquatting package named mlflow-otel-instrumentor was published to PyPI containing malicious code that downloads and executes a remote executable during installation. The payload exhibits worm-like behavior with intentions for persistence via systemd, cryptocurrency mining, and network propagation.

    PyPITyposquattingCompromised package
  2. containedcritical

    Malicious code in cryptgraphy (PyPI)

    A malicious package named cryptgraphy was published to PyPI as a typosquatting attack. The package downloads and executes a remote executable with capabilities for persistence via systemd, cryptocurrency mining, and network propagation.

    2026 08 Mlflow Otel InstrumentorPyPICompromised packageTyposquatting
  3. containedcritical

    Malicious code in scrambleeeer (PyPI)

    The PyPI package scrambleeeer contains malicious code that establishes a reverse shell to a hardcoded location, allowing remote command execution on affected systems. The package was identified as part of a malicious campaign and has been documented by the OpenSSF.

    2026 08 ScrambleeerPyPICompromised package
  4. containedcritical

    Malicious code in reqcrypts (PyPI)

    The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.

    2026 08 ReqcryptPyPICompromised packageMalicious commit