Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedhigh

Malicious code in xx-ent-wiki-sm (PyPI)

The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; limited to users who installed the malicious package versions from PyPI.
Ecosystems
Attack vectors
Affected entities
  • xx-ent-wiki-smPyPI package containing malicious code

The xx-ent-wiki-sm package published on PyPI contained malicious code designed to exfiltrate basic system information including IP address and username. The malicious payload was executed during package installation by overriding the install command in setup.py.\n\nAccording to the OpenSSF malicious-packages repository, this package was categorized as a typical pentest-style package with limited harm potential. The exfiltration mechanism targets only basic host metadata rather than sensitive credentials or data.\n\nThe incident was identified and documented by the OpenSSF malicious-packages project (MAL-2025-191939). Users who installed affected versions of xx-ent-wiki-sm from PyPI may have had basic system information exfiltrated during the installation process.

Indicators of compromise

Packages
  • xx-ent-wiki-sm
Hashes
  • 5ebf0745c51c955dbe898efb0f6b721f30dd75edc24b4ee234e8574cee3da9d3

Remediation

  • Uninstall xx-ent-wiki-sm immediately if installed
  • Review system logs for suspicious network activity or data exfiltration during the package installation period
  • Rotate credentials and review account activity if the package was installed on systems with sensitive access
  • Monitor for any unauthorized access using the exfiltrated IP or username information
  • Check PyPI and package management tools for any similar suspicious packages

Sources

  1. GitHub Advisory GHSA-ff24-vg94-52wq · GitHub Advisory Database

Cite this entry

"Malicious code in xx-ent-wiki-sm (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-xx-ent-wiki-sm-pypi-177sqq

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in alphalend-abi (PyPI)

    The alphalend-abi PyPI package contained malicious code that exfiltrates sensitive files containing SUI private keys to a private GitHub repository. The malicious behavior is triggered on package import and on every Python startup via PTH file abuse.

    2026 08 Alphalend LayoutsPyPICompromised package
  2. containedcritical

    Malicious code in alphalend-layouts (PyPI)

    The PyPI package alphalend-layouts contained malicious code that harvested Sui keystores, private keys, and environment secrets from installer systems and uploaded them to an attacker-controlled GitHub repository. The attack was triggered both during installation and on first import, with credentials deliberately obfuscated to evade detection.

    PyPICompromised packageMalicious commit
  3. containedcritical

    Malicious code in idnna (PyPI)

    A malicious package named idnna was published to PyPI, imitating a legitimate library. During installation, the package executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    PyPITyposquattingCompromised package
  4. containedcritical

    Malicious code in pydanticc (PyPI)

    The PyPI package pydanticc is a typosquatting attack imitating the popular pydantic library. During installation, it executes obfuscated code that downloads and runs a malicious executable, exfiltrating cryptocurrency wallet data and potentially other sensitive information.

    2026 08 FlasqPyPITyposquattingCompromised package