Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

Malicious code in walmart-genai-trace (PyPI)

walmart-genai-trace, a malicious package on PyPI, exfiltrates basic host information (IP, username) upon installation or import. The package overrides the install command in setup.py to execute malicious code during installation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
PyPI users who installed walmart-genai-trace
Ecosystems
Attack vectors
Affected entities
  • walmart-genai-traceMalicious PyPI package

A malicious package named walmart-genai-trace was published to PyPI with the primary purpose of exfiltrating basic system information from affected hosts. The package contains code designed to extract data such as IP addresses and usernames.\n\nThe malicious code is executed during the installation phase by overriding the install command in setup.py, ensuring execution occurs when users install the package via pip. This is a common technique used to compromise systems at installation time.\n\nThe package was identified and attributed to the OpenSSF's malicious-packages repository. It was categorized as a low-harm pentest-style package, though it still poses a risk to any user who installed it. The incident appears to have been detected and addressed, with the package likely removed or flagged on PyPI.

Indicators of compromise

Packages
  • walmart-genai-trace

Remediation

  • Remove walmart-genai-trace from all systems where it was installed
  • Audit systems that may have installed this package for signs of data exfiltration or unauthorized access
  • Review network logs for suspicious outbound connections from affected hosts
  • Update pip and verify the integrity of other installed packages
  • Monitor for any credentials or sensitive information that may have been exposed

Sources

  1. GitHub Advisory GHSA-wj6q-qw9c-whxq · GitHub Advisory Database

Cite this entry

"Malicious code in walmart-genai-trace (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 31, 2026; last updated July 31, 2026. https://supplychainattack.org/incident/malicious-code-in-walmart-genai-trace-pypi-1nw64e

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in cognikit (PyPI)

    Multiple malicious PyPI packages (cognikit, aiassistcore, aichannel) were discovered containing infostealer functionality, cryptocurrency wallet address replacement, browser data exfiltration, remote access capabilities, and malicious browser extensions. The campaign is attributed to North Korea's "Contagious Interview" operation and uses these packages as dependencies in malicious interview assessments and cryptocurrency projects.

    Contagious InterviewPyPICompromised packageMalicious commit
  2. containedcritical

    Malicious code in aiprepkit (PyPI)

    Multiple malicious Python packages (aiprepkit, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware designed to replace cryptocurrency wallet addresses, exfiltrate browser data, establish remote control, and deploy malicious browser extensions, with IoCs consistent with North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in catalogai (PyPI)

    Multiple malicious Python packages (catalogai, cognikit, aiassistcore, aichannel) were published to PyPI as part of a coordinated campaign. The packages contain infostealer malware with capabilities including cryptocurrency wallet address replacement, browser data exfiltration, remote access, and malicious browser extension installation, attributed to North Korea's "Contagious Interview" campaign.

    Contagious InterviewPyPICompromised packageMalicious commit
  4. resolvedcritical

    Malicious code in reguestsc (PyPI)

    A malicious package named reguestsc was published to PyPI as a typosquat of a legitimate library. The package contained injected code that downloads and executes a remote executable (identified as salatstealer infostealer malware) upon import.

    PyPITyposquattingCompromised package