Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedhigh

Malicious code in yhaplo1 (PyPI)

Malicious package yhaplo1 was published to PyPI as a dependency confusion attack. The package contained code to exfiltrate basic system information but did not perform active exfiltration. The attacker identified themselves as a HackerOne user conducting a bug bounty test.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Low; package was identified as a dependency confusion attempt with limited exfiltration capability and no evidence of widespread adoption.
Ecosystems
Attack vectors
Affected entities
  • yhaplo1Malicious package published to PyPI containing code for basic system data exfiltration (IP, username)

A malicious package named yhaplo1 was published to PyPI as part of a dependency confusion attack. The package contained code designed to exfiltrate basic system data such as IP addresses and usernames from infected systems.\n\nThe attacker identified themselves as a HackerOne user and stated the package was created for the purpose of a bug bounty program. According to the OpenSSF malicious packages database, the package did not contain active exfiltration functionality, limiting its actual harm potential.\n\nThe incident was classified as a low-risk pentest-style package under the GENERIC-hackerone-bugbounty campaign. The package has been identified and cataloged by the OpenSSF malicious packages project (MAL-2026-2536).

Indicators of compromise

Packages
  • yhaplo1

Remediation

  • Remove yhaplo1 from any Python environments where it may have been installed
  • Audit systems that may have installed yhaplo1 for signs of compromise or data exfiltration
  • Review PyPI package dependencies to identify and remove any unintended dependency confusion attacks
  • Monitor for similar dependency confusion attempts targeting legitimate package names

Sources

  1. GitHub Advisory GHSA-6q25-qwrp-28hc · GitHub Advisory Database

Cite this entry

"Malicious code in yhaplo1 (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-yhaplo1-pypi-1pc8tf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedhigh

    Malicious code in atlas-internal (PyPI)

    Multiple malicious versions of atlas-internal were published to PyPI containing code that exfiltrates host information (hostname, working directory, username) during installation. The package overrides the egg_info command in setup.py to execute automatically on pip install without user interaction, sending collected data to attacker-controlled out-of-band callback servers.

    PyPICompromised packageDependency confusion
  2. resolvedhigh

    Malicious code in adandu (PyPI)

    The PyPI package 'adandu' was identified as malicious, containing code to exfiltrate basic system information (hostname, path, username) upon installation or import. The package was part of a broader campaign of pentest-themed malicious packages and communicated with domains associated with malicious activity.

    PyPICompromised packageTyposquattingDependency confusion
  3. resolvedhigh

    Malicious code in adandv (PyPI)

    The adandv package on PyPI contained malicious code designed to exfiltrate basic system information (hostname, path, username) to the package author. The package was part of a broader campaign of malicious pentest-themed packages flooding PyPI.

    PyPICompromised packageTyposquattingDependency confusion
  4. resolvedhigh

    Malicious code in zabitog (PyPI)

    Malicious code was discovered in the zabitog package on PyPI. The package contained obfuscated code designed to exfiltrate basic system data such as hostname, IP address, and username. The incident was identified as part of campaign 2026-02-zabitmajeed00 and attributed to OpenSSF's malicious packages research.

    PyPICompromised packageDependency confusion