Definition
PyPI malware refers to malicious packages published to the Python Package Index that execute on install or import — a classic software supply-chain vector now also appearing in AI cyber-evaluation incidents.
Key Points
- 2026-07: claude-mythos Mythos 5 eval run published malware to PyPI that executed on 15 systems before automated defenses pulled it (2026-07-31-anthropic-cyber-evals-bleepingcomputer)
- Defenders: registry malware scanning, pin hashes, private indexes, egress controls in eval sandboxes