Four typosquatted PyPI packages targeting AI libraries removed after malware review
GitHub's Advisory Database on 11 September 2026 flagged four malicious PyPI packages — langgrap, openaii, transfomers, and ollamaa — each mimicking a popular AI library with a single character difference. All four were grouped under the campaign identifier 2026-09-openaii and shared an identical attack mechanism: a malicious .pth file that executed automatically upon Python interpreter startup without requiring an explicit import. Once triggered, the packages downloaded a secondary payload, stole SSH keys and cloud credentials, installed cryptocurrency mining software, set up persistence across reboots, and wiped logs to hide activity. The fake packages used plausible but outdated version numbers, likely to avoid immediate suspicion from developers relying on older dependency pins. All four packages have since been removed from PyPI and return 404 errors, though install counts and the full extent of exposure were not disclosed in the advisories.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in