Malicious code in yolov8mini (PyPI)
The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.
- Disclosed
- Last updated
- Blast radius
- All users who installed yolov8mini from PyPI during the malicious distribution period.
- Ecosystems
- Attack vectors
- Affected entities
- yolov8miniPyPI package containing malicious code
The yolov8mini package distributed via PyPI contained embedded malicious code that activates automatically upon module import. The malicious payload includes a Telegram bot designed to exfiltrate sensitive information from users' systems.\n\nThe bot is capable of stealing passwords from browsers, executing remote commands on the victim's machine, and performing generic data exfiltration. While the package description falsely claimed to be a monitoring tool, the automated activation and targeting of secret values indicate clear malicious intent.\n\nThis incident was identified and attributed to campaign 2025-03-yolov8mini by the OpenSSF malicious packages project. The attack vector involved distributing the compromised package directly through the PyPI repository, potentially affecting all users who installed yolov8mini during the malicious distribution window.\n\nThe package has been reported with hash a9222d20b84ed716d5bdf81f1da1d0f088fc7482894c8f25a5d1f757cc477ba9 and is documented in the OpenSSF malicious packages database as MAL-2025-3484.
Indicators of compromise
- Packages
- yolov8mini
- Hashes
- a9222d20b84ed716d5bdf81f1da1d0f088fc7482894c8f25a5d1f757cc477ba9
Remediation
- Immediately uninstall yolov8mini from all affected systems
- Scan systems for signs of Telegram bot activity and unauthorized command execution
- Reset browser passwords and check for unauthorized access to password managers
- Review system logs for suspicious remote command execution
- Monitor network traffic for connections to Telegram bot infrastructure
- Consider this a full system compromise and perform thorough security audit
- Use alternative, verified YOLOv8 packages from official sources
Sources
- GitHub Advisory GHSA-h4m7-fg96-xx35 · GitHub Advisory Database
Cite this entry
"Malicious code in yolov8mini (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-yolov8mini-pypi-3tmfhd
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package - resolvedcritical
Malicious code in ziphash (PyPI)
The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.
2025 11 UzipPyPICompromised package