Product
PyPI
- First Reported
- Jul 7, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (4)
- onto the dark web. Another victim was LiteLLM, where attackers uploaded a malicious package directly to PyPi. Telnyx had a similar compromise as LiteLLM, with publication through PyPi. Retrospective: How Malicious Software Updates Poison Development Environments
- Campaigns like Shai-Hulud have moved through the npm and, in later waves, PyPI ecosystems, spreading via packages that carry valid provenance and trusted signatures. Trusted Software Packages Are Becoming a Ransomware Delivery Vector
- attempted social engineering against real people, and in one case pushed a malicious Python package to PyPI, where it was downloaded and executed on fifteen systems during the hour it stayed up. Meta has also Four AI-Agent Intrusions Highlight Persistent, Adaptive Attack Behavior
- Socket’s AI scanner detected a cluster of npm and PyPI malware published on July 7, 2026. The 17 packages, published nearly simultaneously, target SDK developers and users of the popular PaySafe, Skrill and Neteller Typosquatted npm and PyPI Packages Steal Secrets from Payment-App Developers
Malware (9)
People (1)
Threat Actors (3)
MITRE ATT&CK (17)
Vendors (10)
Products (15)
Tools (1)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.