Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in yeahmankema (PyPI)

Malicious code was published in the yeahmankema package on PyPI. The package exfiltrates screenshots and network information to a hardcoded target, functioning as spyware.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed the malicious yeahmankema package from PyPI
Ecosystems
Attack vectors
Threat actor
Affected entities
  • yeahmankemaPyPI package containing malicious code

The yeahmankema package published on PyPI contained malicious code designed to steal sensitive information from infected systems. The package exfiltrates screenshots and network information to a hardcoded command-and-control target.\n\nThe malicious package was part of the 2026-05-crayrandomiz campaign and employed obfuscation techniques to evade detection. The package was identified and attributed to the OpenSSF malicious-packages repository.\n\nUsers who installed this package are at risk of information theft and system compromise. The package should be removed immediately from any affected systems.

Indicators of compromise

Packages
  • yeahmankema

Remediation

  • Immediately uninstall the yeahmankema package from all systems using 'pip uninstall yeahmankema'
  • Scan affected systems for signs of compromise, including unauthorized network connections and suspicious processes
  • Review system logs and network traffic for evidence of data exfiltration
  • Change credentials and review account activity on any systems that had the package installed
  • Monitor for unauthorized access or data breaches on affected systems
  • Report the incident to your security team and consider notifying relevant parties if sensitive data was exposed

Sources

  1. GitHub Advisory GHSA-8hvp-pp6m-8c3p · GitHub Advisory Database

Cite this entry

"Malicious code in yeahmankema (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-yeahmankema-pypi-1i9u0e

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adv2099m7 (PyPI)

    Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in adrandom (PyPI)

    The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  4. resolvedcritical

    Malicious code in ziphash (PyPI)

    The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.

    2025 11 UzipPyPICompromised package