Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in yolov8mini (PyPI)

The yolov8mini package on PyPI contained malicious code that automatically launches a Telegram bot capable of stealing browser passwords, executing arbitrary commands, and exfiltrating data. The package was identified as part of a 2025-03 malicious campaign and has been reported to the OpenSSF malicious packages database.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed yolov8mini from PyPI during the malicious distribution period.
Ecosystems
Attack vectors
Affected entities
  • yolov8miniPyPI package containing malicious code

The yolov8mini package distributed via PyPI contained embedded malicious code that activates automatically upon module import. The malicious payload includes a Telegram bot designed to exfiltrate sensitive information from users' systems.\n\nThe bot is capable of stealing passwords from browsers, executing remote commands on the victim's machine, and performing generic data exfiltration. While the package description falsely claimed to be a monitoring tool, the automated activation and targeting of secret values indicate clear malicious intent.\n\nThis incident was identified and attributed to campaign 2025-03-yolov8mini by the OpenSSF malicious packages project. The attack vector involved distributing the compromised package directly through the PyPI repository, potentially affecting all users who installed yolov8mini during the malicious distribution window.\n\nThe package has been reported with hash a9222d20b84ed716d5bdf81f1da1d0f088fc7482894c8f25a5d1f757cc477ba9 and is documented in the OpenSSF malicious packages database as MAL-2025-3484.

Indicators of compromise

Packages
  • yolov8mini
Hashes
  • a9222d20b84ed716d5bdf81f1da1d0f088fc7482894c8f25a5d1f757cc477ba9

Remediation

  • Immediately uninstall yolov8mini from all affected systems
  • Scan systems for signs of Telegram bot activity and unauthorized command execution
  • Reset browser passwords and check for unauthorized access to password managers
  • Review system logs for suspicious remote command execution
  • Monitor network traffic for connections to Telegram bot infrastructure
  • Consider this a full system compromise and perform thorough security audit
  • Use alternative, verified YOLOv8 packages from official sources

Sources

  1. GitHub Advisory GHSA-h4m7-fg96-xx35 · GitHub Advisory Database

Cite this entry

"Malicious code in yolov8mini (PyPI)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 21, 2026; last updated July 21, 2026. https://supplychainattack.org/incident/malicious-code-in-yolov8mini-pypi-3tmfhd

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in afrit-name (PyPI)

    Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.

    PyPICompromised package
  2. resolvedcritical

    Malicious code in adv2099m7 (PyPI)

    Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.

    PyPICompromised package
  3. resolvedcritical

    Malicious code in adrandom (PyPI)

    The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.

    EsquelesquadPyPICompromised package
  4. resolvedcritical

    Malicious code in ziphash (PyPI)

    The ziphash package on PyPI contained malicious code that downloads and executes multi-stage malware during archive-support class initialization. The malware exhibits obfuscation and remote code execution capabilities, classified as part of the 2025-11-uzip campaign.

    2025 11 UzipPyPICompromised package