This page may contain stale information. Last updated: 2026-08-14
Definition
PyPI malware refers to malicious packages published to the Python Package Index that execute on install or import — a classic software supply-chain vector now also appearing in AI cyber-evaluation incidents.
Key Points
-
2026-08: LiteLLM 1.82.7/1.82.8 ~40-minute PyPI window still producing live secrets months later (secret-rotation-failure)
-
2026-07: claude-mythos Mythos 5 eval run published malware to PyPI that executed on 15 systems before automated defenses pulled it (2026-07-31-anthropic-cyber-evals-bleepingcomputer)
-
Defenders: registry malware scanning, pin hashes, private indexes, egress controls in eval sandboxes