Malicious code in trtllm-subdir-test (PyPI)
The PyPI package trtllm-subdir-test contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
- Disclosed
- Last updated
- Blast radius
- Low to moderate; limited to users who installed the malicious package version(s).
- Ecosystems
- Attack vectors
- Affected entities
- trtllm-subdir-testPyPI package containing malicious code
The trtllm-subdir-test package published on PyPI contained malicious code designed to exfiltrate basic system information from the host upon installation or module import. The package has no legitimate functionality beyond this data exfiltration.\n\nThe attack was implemented by overriding the install command in setup.py to execute malicious code during the package installation process. This ensures the payload runs automatically when users install the package via pip.\n\nThe malicious package was identified and attributed to the OpenSSF's malicious-packages repository (MAL-2026-11426). The incident was categorized as a typical pentest-style package with limited harm potential, though it demonstrates the risk of installing untrusted packages from public repositories.\n\nUsers who installed this package should assume their basic system information (IP address, username) may have been exfiltrated and should monitor for any suspicious activity.
Indicators of compromise
- Packages
- trtllm-subdir-test
Remediation
- Remove the trtllm-subdir-test package immediately from all affected systems using 'pip uninstall trtllm-subdir-test'
- Review system logs and network traffic for evidence of data exfiltration
- Monitor accounts and systems for unauthorized access or activity
- Verify the integrity of other installed packages, particularly those from untrusted sources
- Use package verification tools and check PyPI advisories before installing packages
- Consider using dependency scanning tools to detect malicious packages in your supply chain
Sources
- GitHub Advisory GHSA-2fm3-ggxx-45vm · GitHub Advisory Database
Cite this entry
"Malicious code in trtllm-subdir-test (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 1, 2026; last updated August 1, 2026. https://supplychainattack.org/incident/malicious-code-in-trtllm-subdir-test-pypi-1e2ccg
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedhigh
Malicious code in nvtorch-oot-nightly (PyPI)
The PyPI package nvtorch-oot-nightly contained malicious code that exfiltrates basic host information (IP address, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
PyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code was discovered in the asdk-plugin-legacy package on PyPI. The package exfiltrates basic host information (IP, username) upon installation or import, with no legitimate functionality.
PyPICompromised package - resolvedhigh
Malicious code in asdk-plugin-ai-platform (PyPI)
The PyPI package asdk-plugin-ai-platform contained malicious code that exfiltrates basic host information (IP, username) upon installation or module import. The package overrides the install command in setup.py to execute the malicious payload during installation.
PyPICompromised package - containedhigh
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code was published in the asdk-plugin-alphagen package on PyPI (version 9999.0.0). The package exfiltrates basic host information (IP, username) during installation and communicates with a domain associated with malicious activity.
PyPICompromised package