MAL-2026-17472

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anthropic-sdk/MAL-2026-17472.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17472
Published
2026-10-04T19:09:32Z
Modified
2026-10-05T04:15:04Z
Summary
Malicious code in anthropic-sdk (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511)

The package publishes as anthropic-sdk and re-exports the official anthropic client's symbols (from anthropic import *; re-exports of Anthropic/AsyncAnthropic), presenting itself as a drop-in for the official SDK. On import anthropic_sdk, __init__.py imports a _usage module that auto-runs a boot routine. That routine increments a run counter persisted to ~/.config/anthropic-sdk/usage.json and, from the third import onward, fetches https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py — a third-party user's GitHub repository on a mutable branch, unrelated to Anthropic and with no pin or integrity check — then caches the response base64-encoded to ~/.config/anthropic-sdk/lr.json, compiles it, exec()s it, and calls its entry() function. The import-count gate before the first fetch and the base64-at-rest caching of the fetched source serve no legitimate update-check purpose and are consistent with sandbox/analysis evasion. Whoever controls the referenced GitHub repository controls arbitrary code execution on any machine that imports this package.

Source: kam193 (6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442)

During import, package downloads a remote script, fingerprints the environment looking for sandbox signs, and after a delay exfiltrates sensitive data: credentials, env variables, AI chat files, SSH keys and so on. If exfiltration via HTTPS fails, it attempts DNS-based exfiltration. Additionally, package uses DNS to centrally hold execution.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-10-anthropic-sdk

Reasons (based on the campaign):

  • impersonation

  • Downloads and executes a remote malicious script.

  • The package contains code to detect if it is running in a sandbox environment.

  • obfuscation

  • exfiltration-credentials

  • files-exfiltration

  • exfiltration-env-variables

  • exfiltration-ssh-keys

Database specific
{
    "iocs":  {
        "domains":  [
            "telemetry-edge.net",
            "x.telemetry-edge.net"
        ],
        "urls":  [
            "https://telemetry-edge.net/api/v2/ingest",
            "https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py"
        ]
    },
    "malicious-packages-origins":  [
        {
            "id":  "pypi/2026-10-anthropic-sdk/anthropic-sdk",
            "import_time":  "2026-10-04T19:41:26.816743524Z",
            "modified_time":  "2026-10-04T19:09:32.670665Z",
            "sha256":  "6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442",
            "source":  "kam193",
            "versions":  [
                "0.1.0"
            ]
        },
        {
            "id":  "pypi/2026-10-anthropic-sdk/anthropic-sdk",
            "import_time":  "2026-10-04T20:59:58.584721257Z",
            "modified_time":  "2026-10-04T19:09:32.670665Z",
            "sha256":  "84360a33b408842fe15f46b64b7c4c7b2e114e6973694d0f3870e205811c2457",
            "source":  "kam193",
            "versions":  [
                "0.1.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-021009",
            "import_time":  "2026-10-05T03:57:38.417930809Z",
            "modified_time":  "2026-10-05T03:34:50Z",
            "sha256":  "500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511",
            "source":  "amazon-inspector",
            "versions":  [
                "0.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

PyPI / anthropic-sdk

Package

Name
anthropic-sdk
View open source insights on deps.dev
Purl
pkg:pypi/anthropic-sdk

Affected ranges

Affected versions

0.*
0.1.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "anthropic_sdk/_check.py",
            "sha256":  "c899f84c79509df93e9af69d71a404435c17bba3817748a682e52071ae361d47",
            "tlsh":  "bd413eb3a411a8a3c247d65c4a04e9e1a32b7d8b3913e8b6bedc13605f85471c1b6ed8"
        },
        {
            "path":  "anthropic_sdk/_usage.py",
            "sha256":  "06a1e08e2f6a90b7f1b1d3dd1bb9a3f306d6424b4b616891761eedc3c7157704",
            "tlsh":  "58218c7ac80a7d22c297471e4668c4f216667f577f021429f8ddf324af880e5d13e269"
        },
        {
            "path":  "anthropic_sdk/__init__.py",
            "sha256":  "244ce6ffe0fe85213a36ee2849434ea39be69820b7414d9ebba3db9b95baf066",
            "tlsh":  "3de06802923f2ae383230f487a38c0a1077460a7b95b3059da9eb7202fc4200fd4142a"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "anthropic_sdk-0.1.0-py3-none-any.whl",
            "hashes":  {
                "blake2b_256":  "e94c06e031bd83aa91fd3ca876dcd9cefe8e48994f6e4899b4d1d41e0538a335",
                "md5":  "c570edfdda5fb9a423ae9bdfcafab4da",
                "sha256":  "af716c6ae37c94b76b54753718b2cdeb7147383523a311a559b0b40628466b5f"
            }
        },
        {
            "filename":  "anthropic_sdk-0.1.0.tar.gz",
            "hashes":  {
                "blake2b_256":  "c5bda00b783ca281ae2ab36e9bb1ce0928025194d1aa66d9ce0a0a15254a189a",
                "md5":  "d2b6e702a1029ddb4aa1db1e6b152f37",
                "sha256":  "88aa47608004c5485a3623a0cb6c9675dca9a08ef5da945900deed08ea5a40ed"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/anthropic-sdk/MAL-2026-17472.json"