Malicious code in xx-ent-wiki-sm (PyPI)
The PyPI package xx-ent-wiki-sm contained malicious code that exfiltrates basic host information (IP, username) during installation. The package overrides the install command in setup.py to execute the malicious payload.
- Disclosed
- Last updated
- Blast radius
- Unknown; limited to users who installed the malicious package versions from PyPI.
- Ecosystems
- Attack vectors
- Affected entities
- xx-ent-wiki-smPyPI package containing malicious code
The xx-ent-wiki-sm package published on PyPI contained malicious code designed to exfiltrate basic system information including IP address and username. The malicious payload was executed during package installation by overriding the install command in setup.py.\n\nAccording to the OpenSSF malicious-packages repository, this package was categorized as a typical pentest-style package with limited harm potential. The exfiltration mechanism targets only basic host metadata rather than sensitive credentials or data.\n\nThe incident was identified and documented by the OpenSSF malicious-packages project (MAL-2025-191939). Users who installed affected versions of xx-ent-wiki-sm from PyPI may have had basic system information exfiltrated during the installation process.
Indicators of compromise
- Packages
- xx-ent-wiki-sm
- Hashes
- 5ebf0745c51c955dbe898efb0f6b721f30dd75edc24b4ee234e8574cee3da9d3
Remediation
- Uninstall xx-ent-wiki-sm immediately if installed
- Review system logs for suspicious network activity or data exfiltration during the package installation period
- Rotate credentials and review account activity if the package was installed on systems with sensitive access
- Monitor for any unauthorized access using the exfiltrated IP or username information
- Check PyPI and package management tools for any similar suspicious packages
Sources
- GitHub Advisory GHSA-ff24-vg94-52wq · GitHub Advisory Database
Cite this entry
"Malicious code in xx-ent-wiki-sm (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-xx-ent-wiki-sm-pypi-177sqq
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in ziphash (PyPI)
The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.
2025 11 UzipPyPICompromised package